Cross-Site Scripting Vulnerability in Microsoft Office SharePoint
CVE-2026-69690

4.6MEDIUM

What is CVE-2026-69690?

An improper neutralization of input during web page generation in Microsoft Office SharePoint enables an authorized attacker to exploit the system through cross-site scripting. This vulnerability allows attackers to conduct spoofing attacks that could compromise user sessions and manipulate content viewed by users over the network.

Affected Version(s)

Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.20326.20090

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.