SB2026090911 - Multiple vulnerabilities in Microsoft SharePoint Server
Published: September 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 10 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-69268)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute code.
The vulnerability exists due to improper access control in the site export operation when starting a site export operation. A remote user can start a site export operation that does not correctly enforce permission checks on sub-sites to execute code.
Exploitation requires site-management permissions on a SharePoint site.
2) Improper access control (CVE-ID: CVE-2026-69282)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in Microsoft Office SharePoint event receiver definition handling when processing a specially crafted event receiver definition. A remote user can submit a specially crafted event receiver definition that causes the server to load an attacker-specified code library and construct an attacker-specified type before authorization is verified to execute arbitrary code.
List-level permissions on a SharePoint site are required. User interaction is not required.
3) Cross-site scripting (CVE-ID: CVE-2026-69402)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when rendering uploaded malicious content. A remote user can upload malicious content and convince another user to visit or interact with it to perform spoofing.
User interaction is required for exploitation.
4) Execution with unnecessary privileges (CVE-ID: CVE-2026-69409)
CWE-ID: CWE-250 - Execution with Unnecessary Privileges
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to execution with unnecessary privileges in Microsoft Office SharePoint when handling network requests. A remote user can access legal-hold and eDiscovery metadata to disclose sensitive information.
The disclosed metadata can include hold titles, descriptions, managers, and search criteria that the user is not authorized to view.
5) Cross-site scripting (CVE-ID: CVE-2026-69417)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when generating web pages from uploaded content. A remote user can upload malicious content to perform spoofing.
Exploitation requires another user to visit or interact with the malicious content.
6) Execution with unnecessary privileges (CVE-ID: CVE-2026-69464)
CWE-ID: CWE-250 - Execution with Unnecessary Privileges
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to execution with unnecessary privileges in Microsoft Office SharePoint when handling requests over a network. A remote user can execute operations with unnecessary privileges to escalate privileges.
7) Cross-site scripting (CVE-ID: CVE-2026-69615)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when rendering a malicious site. A remote privileged user can send a victim a malicious site and convince them to open it to perform spoofing.
User interaction is required to open the malicious site.
8) Cross-site scripting (CVE-ID: CVE-2026-69690)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when rendering uploaded malicious content. A remote user can upload malicious content and convince another user to visit or interact with it to perform spoofing.
User interaction is required for exploitation.
9) Missing Authorization (CVE-ID: CVE-2026-69724)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to missing authorization in Microsoft Office SharePoint when handling network-based requests. A remote user can execute code remotely to execute arbitrary code.
Exploitation requires Manage List permissions.
10) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-69804)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a time-of-check time-of-use race condition in Microsoft Office SharePoint when winning a race condition. A remote user can win a race condition to execute arbitrary code.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69268
- https://support.microsoft.com/help/5002908
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69282
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69402
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69409
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69417
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69464
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69615
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69690
- https://www.microsoft.com/en-us/download/details.aspx?id=108810
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69724
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-69804