Cross-Site Scripting Vulnerability in Microsoft Office SharePoint
CVE-2026-45462

4.6MEDIUM

What is CVE-2026-45462?

An input validation issue in Microsoft Office SharePoint permits an authorized attacker to execute actions that could lead to content spoofing. This vulnerability arises from the improper handling of user-supplied input during the generation of web pages, allowing attackers to manipulate data displayed to users. As a result, they can present deceptive content, potentially compromising user trust and data integrity. It is crucial to apply the recommended patches and updates to mitigate any risks associated with this vulnerability.

Affected Version(s)

Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5556.1005

Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20153

Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.19725.20384

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.