Execution with unnecessary privileges in Microsoft SharePoint Server - CVE-2026-69409

 

Execution with unnecessary privileges in Microsoft SharePoint Server - CVE-2026-69409

Published: September 8, 2026


Vulnerability identifier: #VU147670
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-69409
CWE-ID: CWE-250
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to execution with unnecessary privileges in Microsoft Office SharePoint when handling network requests. A remote user can access legal-hold and eDiscovery metadata to disclose sensitive information.

The disclosed metadata can include hold titles, descriptions, managers, and search criteria that the user is not authorized to view.


Affected software

Microsoft SharePoint Server

How to mitigate CVE-2026-69409

Install security update from vendor's website.

Microsoft SharePoint Server - update to 16.0.20326.20090

External References

Related Security Bulletins