Server-Side Request Forgery (SSRF) in Microsoft SharePoint Server - CVE-2026-55051

 

Server-Side Request Forgery (SSRF) in Microsoft SharePoint Server - CVE-2026-55051

Published: July 17, 2026


Vulnerability identifier: #VU138279
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55051
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to server-side request forgery (ssrf) in Microsoft Office SharePoint when handling network requests. A remote user can send a specially crafted request to disclose sensitive information.

An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.


Affected software

Microsoft SharePoint Server

How to mitigate CVE-2026-55051

Install security update from vendor's website.

Microsoft SharePoint Server - addressed in versions 16.0.5561.1001, 16.0.10417.20175, 16.0.19725.20434

External References

Related Security Bulletins