Improper access control in Microsoft SharePoint Server - CVE-2026-69282
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in Microsoft Office SharePoint event receiver definition handling when processing a specially crafted event receiver definition. A remote user can submit a specially crafted event receiver definition that causes the server to load an attacker-specified code library and construct an attacker-specified type before authorization is verified to execute arbitrary code.
List-level permissions on a SharePoint site are required. User interaction is not required.