CVE-2026-26105

8.1

Microsoft · Office SharePoint

A cross-site scripting vulnerability exists in Microsoft Office SharePoint, allowing an unauthenticated attacker to perform spoofing over a network.

Executive summary

A high-severity cross-site scripting vulnerability in Microsoft Office SharePoint allows unauthenticated attackers to conduct spoofing attacks, posing a significant risk to user integrity.

Vulnerability

This vulnerability is caused by improper neutralization of input during web page generation, classified as CWE-79. An unauthenticated attacker can leverage this flaw to inject malicious scripts into web pages viewed by other users.

Business impact

The ability for an unauthenticated attacker to perform spoofing via cross-site scripting poses a severe risk to organizational data and session integrity. With a CVSS score of 8.1, the vulnerability represents a high threat to business operations, as it could lead to the theft of session tokens, unauthorized actions taken on behalf of users, or the dissemination of fraudulent content.

Remediation

Immediate Action: Administrators must apply the latest security updates provided by Microsoft in the official update guide to reach the fixed build versions listed above.

Proactive Monitoring: Security teams should monitor web server access logs for anomalous request patterns or URI parameters containing script-like characters.

Compensating Controls: Deploy or update Web Application Firewall (WAF) rules to detect and block common cross-site scripting payloads targeting SharePoint environments.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Given the high CVSS score and the potential for unauthorized user interaction, this vulnerability should be prioritized for remediation. IT administrators are advised to verify their current SharePoint build versions against the provided patch levels and deploy the necessary Microsoft security updates immediately to protect the environment.

More Microsoft CVEs

Sources