Cross-site scripting in Microsoft SharePoint Server - CVE-2026-69417
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when generating web pages from uploaded content. A remote user can upload malicious content to perform spoofing.
Exploitation requires another user to visit or interact with the malicious content.