Sceawere

Vulnerability Detail

CVE-2026-64897UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office SharePoint XSS Spoofing Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.6
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft SharePoint Enterprise Server 2016
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.6",
  "pubDate": "2026-08-11T17:18:50.440Z",
  "pubdate": "2026-08-11T17:18:50.440Z",
  "executiveSummary": "This vulnerability involves an improper neutralization of input during web page generation, commonly classified as Cross-Site Scripting (XSS), affecting Microsoft Office SharePoint.\nAn authenticated attacker can exploit this security flaw to perform spoofing attacks over a network.\nThe primary impact of this vulnerability includes the potential execution of malicious scripts within the context of a victim's session, leading to unauthorized actions, data exposure, or interface manipulation.\nSuccessful exploitation requires network access to the vulnerable SharePoint instance and authorization to interact with the web application input mechanisms.\nThe risk implication is significant as it undermines the integrity and confidentiality of user sessions interacting with the SharePoint platform, potentially allowing attackers to masquerade as legitimate users or manipulate displayed content.\nDefense strategies must focus on proper input sanitization and output encoding within the affected web generation routines of the product.",
  "technicalDetails": "The vulnerability stems from insufficient validation, sanitization, and neutralization of user-supplied input prior to rendering it within web pages generated by Microsoft Office SharePoint.\nBecause the application fails to properly encode or escape untrusted data before reflecting it in the Document Object Model (DOM), an attacker can inject malicious scripts, typically JavaScript, into parameters processed by the web application.\nThe vulnerable component resides within the web page generation and rendering engine of Microsoft Office SharePoint.\nThe attack flow proceeds as follows: First, the authenticated attacker crafts a malicious payload containing executable script content designed to mimic legitimate interface elements or manipulate session behavior. Second, the attacker submits this payload to the SharePoint application via input vectors processed during web page creation. Third, when a victimized user requests the affected web page, the SharePoint server includes the unneutralized input in the HTTP response. Fourth, the victim's browser parses the response, executing the injected script within the security context of the vulnerable application.\nThis enables the attacker to achieve spoofing capabilities over the network, as the script can alter the visual presentation of the page or interact with the application on behalf of the user.\nExploitation requires network connectivity to the target SharePoint server and valid user credentials or an authorization level sufficient to supply input that gets reflected or stored in the web interface.\nPost-exploitation impact includes session hijacking, unauthorized data access, and interface spoofing, which can be leveraged to deceive users into disclosing sensitive information or performing unintended administrative or transactional actions."
}
CVE-2026-64897: Microsoft Office SharePoint XSS Spoofing Vulnerability (MEDIUM Severity, CVSS: 4.6) - Sceawere