CVE-2026-69282

8.8

Microsoft · SharePoint Server Subscription Edition

A vulnerability in Microsoft SharePoint Server allows an authenticated attacker to achieve remote code execution through improper access control.

Executive summary

A critical access control flaw in Microsoft SharePoint Server Subscription Edition allows authenticated attackers to execute arbitrary code, posing a significant risk of full system compromise.

Vulnerability

The vulnerability is an improper access control issue (CWE-284) that allows an authenticated user with low privileges to execute code over the network.

Business impact

This vulnerability carries a CVSS score of 8.8, reflecting its high impact on confidentiality, integrity, and availability. Successful exploitation allows an attacker to execute arbitrary code within the context of the SharePoint server, which could lead to unauthorized data exfiltration, complete system takeover, or further lateral movement within the network.

Remediation

Immediate Action: Update Microsoft SharePoint Server Subscription Edition to version 16.0.20326.20090 or later to apply the necessary security patches.

Proactive Monitoring: Audit SharePoint access logs for unusual user activity, particularly requests involving administrative functions or unexpected execution of server-side scripts.

Compensating Controls: Implement Web Application Firewall (WAF) rules designed to filter suspicious traffic and restrict access to sensitive SharePoint endpoints to authorized network segments only.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for remote code execution, organizations should treat this vulnerability with high urgency. Administrators must prioritize applying the vendor provided patch to all affected SharePoint instances immediately to prevent potential exploitation by authenticated actors.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources