CVE-2026-69465

8.8

Microsoft · SharePoint Server Subscription Edition

A missing authorization flaw in Microsoft SharePoint Server Subscription Edition allows an authenticated attacker to execute arbitrary code over the network.

Executive summary

A high severity authorization vulnerability in Microsoft SharePoint Server Subscription Edition permits remote code execution by authenticated attackers.

Vulnerability

The vulnerability is categorized as CWE-862, specifically a missing authorization flaw. It allows an attacker with low-level privileges to perform unauthorized actions, ultimately resulting in remote code execution.

Business impact

The ability for an authenticated user to execute code remotely poses a severe threat to data integrity, confidentiality, and system availability. Given the CVSS score of 8.8, this vulnerability represents a significant risk that could lead to a full system compromise, potentially allowing lateral movement within the network or the exfiltration of sensitive organizational data.

Remediation

Immediate Action: Update Microsoft SharePoint Server Subscription Edition to version 16.0.20326.20074 or later as specified in the Microsoft security update guide.

Proactive Monitoring: Review SharePoint server access logs and audit trails for unusual administrative activity or unexpected process execution patterns.

Compensating Controls: Implement strict network segmentation and ensure that SharePoint instances are protected by a Web Application Firewall (WAF) configured to inspect traffic for unauthorized command patterns.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations running Microsoft SharePoint Server Subscription Edition must treat this vulnerability with high urgency. Prioritize the application of the official security update to all affected instances to eliminate the risk of remote code execution. Ensure that authentication controls remain robust to prevent unauthorized users from gaining the initial access required to trigger this flaw.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources