CVE-2026-69724

8.8

Microsoft · SharePoint Server Subscription Edition

A missing authorization vulnerability in Microsoft SharePoint Server allows an authenticated attacker to achieve remote code execution over the network.

Executive summary

A critical missing authorization flaw in Microsoft SharePoint Server Subscription Edition permits an authenticated attacker to execute arbitrary code, posing a significant risk to system integrity.

Vulnerability

This vulnerability, identified as CWE-862, involves missing authorization checks within the SharePoint framework. It requires the attacker to hold valid, low-level user credentials to trigger the execution of code.

Business impact

The ability for an authenticated user to execute remote code allows for full system compromise, potentially leading to unauthorized data exfiltration, lateral movement within the network, and complete loss of service availability. With a CVSS score of 8.8, this high-severity vulnerability warrants immediate attention to prevent malicious actors from escalating privileges or disrupting core business operations.

Remediation

Immediate Action: Update Microsoft SharePoint Server Subscription Edition to build 16.0.20326.20090 or later to apply the necessary authorization controls.

Proactive Monitoring: Audit SharePoint access logs for suspicious administrative activity or unexpected execution patterns originating from standard user accounts.

Compensating Controls: Deploy Web Application Firewall rules to detect and block anomalous request patterns directed at sensitive SharePoint endpoints until patching is completed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for total system compromise, administrators should prioritize the deployment of the vendor security update across all affected SharePoint environments. Testing and validation of the patch should be performed in a staging environment before pushing to production, ensuring that no business-critical workflows are interrupted by the updated authorization logic.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources