Path traversal in Microsoft products - CVE-2026-45454
Published: June 10, 2026
Vulnerability identifier: #VU134165
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45454
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in Microsoft SharePoint. A remote user can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Server
Microsoft SharePoint Server Subscription Edition
How to mitigate CVE-2026-45454
Install updates from vendor's website.
Microsoft SharePoint Enterprise Server - update to 16.0.5556.1005
Microsoft SharePoint Server - update to 16.0.10417.20153
Microsoft SharePoint Server Subscription Edition - update to 16.0.19725.20384
Microsoft SharePoint Server - update to 16.0.10417.20153
Microsoft SharePoint Server Subscription Edition - update to 16.0.19725.20384