Cross-Site Scripting Vulnerability in Microsoft Office SharePoint
CVE-2026-69402
7.3HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-69402?
A vulnerability exists in Microsoft Office SharePoint that allows for improper neutralization of input during web page generation. This flaw facilitates cross-site scripting (XSS), enabling authorized attackers to execute spoofing attacks within a network. By taking advantage of this vulnerability, attackers may impersonate other users or redirect them to malicious sites, leading to potential data breaches and compromise of sensitive information. Users of affected versions are urged to apply patches and adopt security measures to mitigate the associated risks.
Affected Version(s)
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.20326.20090