Executive brief
Microsoft SharePoint is a widely-used collaboration and document management platform deployed across enterprises. A time-of-check time-of-use race condition allows an authorized user to exploit a timing gap in the application's access controls to execute arbitrary code on affected servers, potentially leading to data theft, system compromise, or lateral movement within an organization's network.
Technical details
This vulnerability is a time-of-check time-of-use (TOCTOU) race condition in Microsoft SharePoint's access control logic. An authenticated attacker can exploit a window between the time when permissions are checked and the time when an action is executed to bypass authorization controls and execute arbitrary code with elevated privileges. The attack requires network access to a SharePoint instance and authentication credentials, but does not require end-user interaction. Successful exploitation allows code execution in the context of the SharePoint application, potentially enabling unauthorized data access or system compromise. Microsoft has released patches through the security update process.
Affected products
- Microsoft SharePoint
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: NVD and Microsoft Security Response Center advisory published