Junglewise Threat Intelligence

CVE-2026-69636: Microsoft Office SharePoint SQL injection

CVE-2026-69636 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft Office SharePoint, Microsoft SharePoint Server. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint contains a SQL injection vulnerability that allows an authorized user to craft malicious queries and potentially extract sensitive information from the underlying database. This could expose confidential business data, customer information, or other sensitive records stored within SharePoint systems.

Technical details

The vulnerability exists in Microsoft Office SharePoint due to improper neutralization of special elements in SQL commands. An authenticated attacker can inject arbitrary SQL code to bypass authentication checks and retrieve unauthorized data. The attack requires network access to the SharePoint instance and valid credentials, but the attacker does not need elevated privileges. Successful exploitation allows an attacker to disclose information from the database. Microsoft has released security updates to remediate this vulnerability.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-09-08: disclosed

References

Related threats