Server-Side Request Forgery in Microsoft Office SharePoint
CVE-2026-69904
3.5LOW
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-69904?
A server-side request forgery vulnerability exists in Microsoft Office SharePoint, which allows an authorized attacker to send crafted requests to internal services and potentially disclose sensitive information over the network. This vulnerability can lead to unauthorized data access, necessitating immediate attention and remediation to protect user data.
Affected Version(s)
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.20326.20082