Cross-site scripting in Microsoft SharePoint Server - CVE-2026-55019

 

Cross-site scripting in Microsoft SharePoint Server - CVE-2026-55019

Published: July 17, 2026


Vulnerability identifier: #VU138273
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-55019
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform spoofing.

The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when handling a malicious link. A remote user can send a specially crafted link and convince the user to open it to perform spoofing.

Successful exploitation could allow limited disclosure of sensitive information and limited modification of disclosed information. User interaction is required to open a crafted link.


Affected software

Microsoft SharePoint Server

How to mitigate CVE-2026-55019

Install security update from vendor's website.

Microsoft SharePoint Server - addressed in versions 16.0.5561.1001, 16.0.10417.20175, 16.0.19725.20434

External References

Related Security Bulletins