Cross-Site Scripting Vulnerability in Microsoft Office SharePoint
CVE-2026-69690
4.6MEDIUM
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-69690?
An improper neutralization of input during web page generation in Microsoft Office SharePoint enables an authorized attacker to exploit the system through cross-site scripting. This vulnerability allows attackers to conduct spoofing attacks that could compromise user sessions and manipulate content viewed by users over the network.
Affected Version(s)
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.20326.20090