Cross-Site Scripting Vulnerability in Microsoft Office SharePoint
CVE-2026-45481

7.3HIGH

What is CVE-2026-45481?

A security issue in Microsoft Office SharePoint can be exploited by an authorized attacker to carry out spoofing attacks via improper handling of input during the web page generation process. This vulnerability opens up potential risks that could lead to unauthorized access or manipulation of data. Organizations using affected versions need to apply necessary patches to mitigate the risk.

Affected Version(s)

Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5556.1005

Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20153

Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.19725.20384

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.