CVE-2026-69464

8.8

Microsoft · SharePoint Server Subscription Edition

A privilege escalation vulnerability in Microsoft SharePoint Server Subscription Edition allows an authorized attacker to gain elevated privileges over the network.

Executive summary

A high-severity privilege escalation vulnerability in Microsoft SharePoint Server Subscription Edition allows authenticated attackers to compromise system integrity and confidentiality.

Vulnerability

The software suffers from an execution with unnecessary privileges flaw, categorized as CWE-250. An attacker who has already authenticated as a standard user can leverage this vulnerability to elevate their access rights within the SharePoint environment.

Business impact

This vulnerability poses a significant risk to organizational security, as it allows a low-privileged user to potentially gain administrative or elevated control over sensitive SharePoint data. With a CVSS score of 8.8, this flaw represents a high risk for unauthorized data access, modification, or complete system compromise. Organizations relying on SharePoint for document management or collaborative workflows face potential data breaches and service disruption if this vulnerability is exploited.

Remediation

Immediate Action: Update Microsoft SharePoint Server Subscription Edition to version 16.0.20326.20090 or later immediately to resolve the underlying privilege management issue.

Proactive Monitoring: Review SharePoint audit logs for anomalous account activity or unexpected permission changes performed by standard user accounts.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced for all SharePoint users and monitor network traffic for unusual patterns originating from authenticated internal segments.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for full privilege escalation, this vulnerability should be treated with high priority. System administrators must schedule and deploy the provided security update to all affected SharePoint instances to prevent unauthorized privilege escalation and ensure the continued integrity of the server environment.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources