Executive brief
Microsoft Office SharePoint contains a SQL injection vulnerability that allows an authorized user to craft malicious queries and potentially extract sensitive information from the underlying database. This could expose confidential business data, customer information, or other sensitive records stored within SharePoint systems.
Technical details
The vulnerability exists in Microsoft Office SharePoint due to improper neutralization of special elements in SQL commands. An authenticated attacker can inject arbitrary SQL code to bypass authentication checks and retrieve unauthorized data. The attack requires network access to the SharePoint instance and valid credentials, but the attacker does not need elevated privileges. Successful exploitation allows an attacker to disclose information from the database. Microsoft has released security updates to remediate this vulnerability.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-09-08: disclosed