Junglewise Threat Intelligence

CVE-2026-69690: Microsoft Office SharePoint cross-site scripting in web page generation

CVE-2026-69690 · Severity: medium · CVSS 4.6 · Published 2026-09-08

Executive brief

Microsoft Office SharePoint contains a cross-site scripting (XSS) vulnerability that allows an authorized attacker to inject malicious scripts into web pages. An attacker with valid credentials could manipulate the appearance of SharePoint pages or perform actions on behalf of users, potentially leading to credential theft, data theft, or account compromise.

Technical details

This is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint's web page generation functionality. The vulnerability exists because user-supplied input is not properly sanitized before being rendered in web pages. An authorized attacker with valid credentials can exploit this flaw by injecting malicious scripts that will execute in the browsers of other users. The attack requires the attacker to have valid account access to SharePoint. An attacker could perform spoofing attacks, steal session cookies, manipulate page content, or redirect users to malicious sites.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-09-08: disclosed

References

Related threats