Executive brief
Microsoft Office SharePoint contains a server-side request forgery vulnerability that allows an authorized user to make the server perform unintended network requests. An attacker with legitimate access could exploit this to disclose sensitive information accessible to the SharePoint server, such as internal network data or credentials.
Technical details
A server-side request forgery (SSRF) vulnerability exists in Microsoft Office SharePoint where insufficient input validation allows an authenticated attacker to craft requests that cause the server to fetch data from arbitrary network locations. The vulnerability requires the attacker to have authorization to access SharePoint. An attacker can leverage this to access internal services, bypass network controls, or retrieve sensitive metadata. Microsoft has released security updates to remediate this issue.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-09-08: disclosed