Execution with unnecessary privileges in Microsoft SharePoint Server - CVE-2026-69409
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to execution with unnecessary privileges in Microsoft Office SharePoint when handling network requests. A remote user can access legal-hold and eDiscovery metadata to disclose sensitive information.
The disclosed metadata can include hold titles, descriptions, managers, and search criteria that the user is not authorized to view.