CVE-2026-70326
8.8Microsoft · SharePoint Server Subscription Edition
A server-side request forgery vulnerability in Microsoft SharePoint Server Subscription Edition allows an authenticated attacker to perform unauthorized actions and elevate privileges over a network.
Executive summary
An authenticated server-side request forgery vulnerability in Microsoft SharePoint Server Subscription Edition poses a significant risk of privilege escalation and unauthorized network access.
Vulnerability
This vulnerability is a Server-Side Request Forgery (SSRF) flaw, identified as CWE-918. It requires an authenticated user with low-level privileges to initiate the attack, which can then be leveraged to escalate privileges within the network environment.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high severity. Successful exploitation could allow an attacker to bypass security controls, leading to potential data exfiltration, service disruption, or full system compromise by interacting with internal resources that are normally inaccessible to the attacker.
Remediation
Immediate Action: Update Microsoft SharePoint Server Subscription Edition to build 16.0.19725.20522 or later immediately.
Proactive Monitoring: Review SharePoint audit logs for unusual request patterns, particularly those originating from internal service accounts or unexpected internal endpoints.
Compensating Controls: Implement strict network segmentation and egress filtering to prevent the server from reaching unauthorized internal or external resources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for privilege escalation, organizations should prioritize patching their SharePoint environments. Applying the vendor-provided update is the only effective way to neutralize the risk of this SSRF vulnerability.