CVE-2026-70326

8.8

Microsoft · SharePoint Server Subscription Edition

A server-side request forgery vulnerability in Microsoft SharePoint Server Subscription Edition allows an authenticated attacker to perform unauthorized actions and elevate privileges over a network.

Executive summary

An authenticated server-side request forgery vulnerability in Microsoft SharePoint Server Subscription Edition poses a significant risk of privilege escalation and unauthorized network access.

Vulnerability

This vulnerability is a Server-Side Request Forgery (SSRF) flaw, identified as CWE-918. It requires an authenticated user with low-level privileges to initiate the attack, which can then be leveraged to escalate privileges within the network environment.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high severity. Successful exploitation could allow an attacker to bypass security controls, leading to potential data exfiltration, service disruption, or full system compromise by interacting with internal resources that are normally inaccessible to the attacker.

Remediation

Immediate Action: Update Microsoft SharePoint Server Subscription Edition to build 16.0.19725.20522 or later immediately.

Proactive Monitoring: Review SharePoint audit logs for unusual request patterns, particularly those originating from internal service accounts or unexpected internal endpoints.

Compensating Controls: Implement strict network segmentation and egress filtering to prevent the server from reaching unauthorized internal or external resources.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for privilege escalation, organizations should prioritize patching their SharePoint environments. Applying the vendor-provided update is the only effective way to neutralize the risk of this SSRF vulnerability.

More Microsoft CVEs