Sceawere

Vulnerability Detail

CVE-2026-57105UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office SharePoint XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft SharePoint Server 2019
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.0",
  "pubDate": "2026-08-11T17:18:04.740Z",
  "pubdate": "2026-08-11T17:18:04.740Z",
  "executiveSummary": "An improper neutralization of input vulnerability, classified as cross-site scripting (XSS), exists within Microsoft Office SharePoint. This security flaw enables an authenticated attacker with network access to execute unauthorized actions, specifically spoofing, within the context of a victim's web session.\nThe vulnerability affects Microsoft Office SharePoint products, posing significant risk implications for organizational collaboration environments where data integrity and user trust are paramount. By leveraging this flaw, malicious actors can manipulate web page generation to inject and execute arbitrary scripts in the browsers of other system users.\nSuccessful exploitation requires the attacker to be authorized within the network and capable of interacting with the vulnerable SharePoint application. The primary impact involves spoofing capabilities, which can lead to unauthorized user actions, session hijacking, or the display of deceptive content, thereby undermining the confidentiality and integrity of web-based interactions within the affected platform.",
  "technicalDetails": "The root cause of the vulnerability stems from insufficient sanitization, filtering, or encoding of user-supplied input prior to its reflection or inclusion in dynamic web page generation by Microsoft Office SharePoint. Specifically, the application fails to adequately neutralize malicious scripts, allowing input data to be interpreted as executable code by the victim's web browser.\nThe vulnerable component resides within the web application rendering engine of Microsoft Office SharePoint, where user-controlled parameters are processed and rendered without proper contextual output encoding. Attack vectors rely on injecting specially crafted payloads containing malicious script code into vulnerable input fields or URL parameters processed by the SharePoint environment.\nThe attack flow proceeds as follows: First, the attacker crafts a malicious input string designed to break out of the intended data context during HTML or JavaScript generation. Second, the attacker delivers this payload to the vulnerable Microsoft Office SharePoint instance, typically via network requests. Third, when an authorized user requests the affected web page, SharePoint incorporates the unneutralized input directly into the HTTP response. Fourth, the victim's browser parses the response, executing the injected script within the security context of the vulnerable origin, thereby facilitating spoofing and secondary malicious behaviors.\nExploitation requires network exposure to the SharePoint application and relies on the victim maintaining an active, authenticated session. Privileges required are limited to those of an authorized user capable of submitting input that gets reflected or stored and subsequently rendered to other users. Post-exploitation impact includes the ability to perform actions on behalf of the victim, manipulate the Document Object Model (DOM) of the affected web page, capture sensitive session tokens, or execute interface spoofing attacks to deceive users."
}
CVE-2026-57105: Microsoft Office SharePoint XSS Vulnerability (HIGH Severity, CVSS: 8.0) - Sceawere