Junglewise Threat Intelligence

CVE-2026-69683: Microsoft Office SharePoint server-side request forgery

CVE-2026-69683 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Office SharePoint is a widely-used platform for document management and team collaboration in enterprise environments. A server-side request forgery vulnerability allows an authorized user to trick the system into making requests on their behalf, potentially exposing sensitive information accessible to the server. This could result in unauthorized disclosure of confidential data or internal system details.

Technical details

This vulnerability is a server-side request forgery (SSRF) in Microsoft Office SharePoint that permits an authenticated attacker to initiate arbitrary network requests from the affected system. The SSRF flaw allows an attacker with valid credentials to disclose sensitive information over the network by manipulating SharePoint to request resources on their behalf. Exploitation requires authentication and network access to the SharePoint service. A patch is available through Microsoft's security updates.

Affected products

  • Microsoft Office SharePoint <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats