Junglewise Threat Intelligence

CVE-2026-69716: Microsoft Office SharePoint SQL injection

CVE-2026-69716 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office SharePoint is a widely-used collaboration and document management platform deployed in enterprise environments. An SQL injection vulnerability allows authorized users with access to the system to execute arbitrary database queries, potentially leading to privilege escalation and unauthorized access to sensitive organizational data stored within SharePoint.

Technical details

This vulnerability involves improper neutralization of special elements in SQL commands, allowing SQL injection attacks within Microsoft Office SharePoint. The flaw permits an authenticated attacker to craft malicious input that is inadequately sanitized before being passed to database queries, enabling arbitrary SQL execution. An attacker with authorization to access SharePoint can leverage this to escalate privileges and access or modify data beyond their intended permissions. The attack is network-accessible and requires prior authentication. Microsoft has issued security patches to remediate this vulnerability.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-09-08: disclosed

References

Related threats