Path Traversal Vulnerability in Microsoft Office SharePoint
CVE-2026-45454
6.5MEDIUM
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 9 June 2026
What is CVE-2026-45454?
A path traversal vulnerability exists in Microsoft Office SharePoint that allows an authorized attacker to bypass directory restrictions and execute arbitrary code over a network. This flaw results from improper limitations on pathname handling, potentially leading to unauthorized access and exploitation of system resources. Affected users are strongly advised to apply the necessary updates to mitigate this risk.
Affected Version(s)
Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5556.1005
Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20153
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.19725.20384