Improper access control in Microsoft SharePoint Server - CVE-2026-69268
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote user to execute code.
The vulnerability exists due to improper access control in the site export operation when starting a site export operation. A remote user can start a site export operation that does not correctly enforce permission checks on sub-sites to execute code.
Exploitation requires site-management permissions on a SharePoint site.