CVE-2026-69273
8.8Microsoft · SharePoint Server Subscription Edition
A flaw in Microsoft SharePoint Server Subscription Edition allows an authenticated attacker to achieve remote code execution via improper access control.
Executive summary
An authenticated attacker can exploit improper access control in Microsoft SharePoint Server Subscription Edition to execute arbitrary code, posing a high risk of total system compromise.
Vulnerability
This vulnerability is caused by improper access control, classified as CWE-284, which permits an authenticated attacker to execute code over the network. The vulnerability requires the attacker to have low-level privileges to interact with the vulnerable SharePoint instance.
Business impact
The potential for unauthorized remote code execution represents a critical threat to organizational data integrity and confidentiality. Given the CVSS score of 8.8, this vulnerability allows an attacker to gain significant control over the SharePoint environment, which could lead to unauthorized data exfiltration, lateral movement within the network, or complete service disruption.
Remediation
Immediate Action: Apply the vendor-provided security update to upgrade the software to version 16.0.20326.20082 or later.
Proactive Monitoring: Review SharePoint access logs for unusual administrative activity or unauthorized attempts to execute scripts and commands from low-privileged user accounts.
Compensating Controls: Implement strict network segmentation and ensure that the SharePoint instance is not exposed to the public internet, using a Web Application Firewall to filter suspicious traffic patterns.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the severity of remote code execution, it is imperative that IT administrators prioritize the deployment of the update to version 16.0.20326.20082. Organizations should verify that all SharePoint Server instances are updated in accordance with Microsoft guidelines to mitigate the risk of unauthorized command execution.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Microsoft Office SharePoint Remote Code Execution Vulnerability Vendor advisory