Server-Side Request Forgery in Microsoft Office SharePoint
CVE-2026-69683

6.5MEDIUM

What is CVE-2026-69683?

An SSRF vulnerability exists in Microsoft Office SharePoint, which allows an authorized attacker to make server-side requests that can disclose sensitive information over the network. This exploitation can compromise the security of the system by revealing internal endpoints and network parameters, potentially leading to further attacks. Users are advised to apply the latest security updates to mitigate this risk.

Affected Version(s)

Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.20326.20082

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.