CVE-2026-69716

8.8

Microsoft · SharePoint Server Subscription Edition

An SQL injection vulnerability in Microsoft SharePoint Server Subscription Edition allows an authenticated attacker to elevate privileges over a network.

Executive summary

A critical SQL injection vulnerability in Microsoft SharePoint Server Subscription Edition permits authorized attackers to perform unauthorized actions and escalate privileges.

Vulnerability

The application is susceptible to an SQL injection attack, classified as CWE-89, where improper neutralization of input allows an attacker with low privileges (authenticated) to execute arbitrary SQL commands.

Business impact

The ability for an authenticated user to perform SQL injection poses a severe risk to data integrity and system security. Successful exploitation could lead to full database compromise, unauthorized access to sensitive information, or complete system takeover, justifying the CVSS score of 8.8.

Remediation

Immediate Action: Update Microsoft SharePoint Server Subscription Edition to version 16.0.20326.20094 or later to apply the necessary security patch.

Proactive Monitoring: Monitor database query logs for unusual or malformed syntax that deviates from standard application traffic patterns.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to detect and block common SQL injection payloads targeted at SharePoint endpoints.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS severity score of 8.8 and the critical nature of privilege escalation, immediate patching is required to secure the environment. Administrators should verify the current build version of their SharePoint infrastructure and apply the fix provided by Microsoft without delay to prevent potential exploitation of this flaw.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources