Executive brief
Microsoft SharePoint, a widely-deployed enterprise collaboration and document management platform, contains a missing authorization vulnerability that could allow an authenticated user to execute arbitrary code remotely. An attacker with valid SharePoint credentials could leverage this flaw to compromise the platform and potentially gain broader access to organizational data and systems.
Technical details
This vulnerability is a missing authorization (CWE-862) flaw in Microsoft Office SharePoint. The vulnerability allows an authenticated attacker to execute arbitrary code over the network without proper authorization checks. The attack requires the attacker to have valid SharePoint credentials and network access to the affected system. Successful exploitation could result in remote code execution (RCE) within the SharePoint environment, potentially leading to data theft, lateral movement, or system compromise. Microsoft has released security updates to remediate this vulnerability.
Affected products
- Microsoft SharePoint <UNKNOWN>
Timeline
- 2026-09-08: disclosed: Vulnerability disclosed publicly