Cross-site scripting in Microsoft SharePoint Server - CVE-2026-69615
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote user to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Office SharePoint when rendering a malicious site. A remote privileged user can send a victim a malicious site and convince them to open it to perform spoofing.
User interaction is required to open the malicious site.