Cross-site scripting in Microsoft SharePoint Server - CVE-2026-69402

 

Cross-site scripting in Microsoft SharePoint Server - CVE-2026-69402

Published: September 8, 2026


Vulnerability identifier: #VU147663
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-69402
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform spoofing.

The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when rendering uploaded malicious content. A remote user can upload malicious content and convince another user to visit or interact with it to perform spoofing.

User interaction is required for exploitation.


Affected software

Microsoft SharePoint Server

How to mitigate CVE-2026-69402

Install security update from vendor's website.

Microsoft SharePoint Server - update to 16.0.20326.20090

External References

Related Security Bulletins