Cross-site scripting in Microsoft SharePoint Server - CVE-2026-55019
Published: July 17, 2026
Microsoft SharePoint Server
Detailed vulnerability description
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when handling a malicious link. A remote user can send a specially crafted link and convince the user to open it to perform spoofing.
Successful exploitation could allow limited disclosure of sensitive information and limited modification of disclosed information. User interaction is required to open a crafted link.