Improper access control in Microsoft SharePoint Server - CVE-2026-56157

 

Improper access control in Microsoft SharePoint Server - CVE-2026-56157

Published: July 17, 2026


Vulnerability identifier: #VU138282
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-56157
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to spoof trusted content.

The vulnerability exists due to improper access control in Microsoft Office SharePoint when handling network requests. A remote user can send crafted requests to spoof trusted content.

The issue can lead to some loss of confidentiality and integrity, but no loss of availability.


Affected software

Microsoft SharePoint Server

How to mitigate CVE-2026-56157

Install security update from vendor's website.

Microsoft SharePoint Server - addressed in versions 16.0.5561.1001, 16.0.10417.20175, 16.0.19725.20434

External References

Related Security Bulletins