Cross-Site Scripting Vulnerability in Microsoft Office SharePoint
CVE-2026-64897
4.6MEDIUM
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-64897?
An improper handling of input in Microsoft Office SharePoint can lead to cross-site scripting, allowing an attacker with valid credentials to exploit this vulnerability. By injecting malicious scripts, the attacker could execute unauthorized actions, potentially misleading users and compromising sensitive information across a network. This weakness highlights the importance of rigorous input validation and security measures in web applications to mitigate such risks.
Affected Version(s)
Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5565.1001
Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20198
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.19725.20522