SQL injection in Microsoft SharePoint Server - CVE-2026-69636
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper neutralization of special elements used in an sql command in Microsoft Office SharePoint when processing sql commands. A remote user can submit a crafted sql command to disclose sensitive information.
Disclosed information may include organizational email addresses, sites, filenames, or file URLs.