Sceawere

Vulnerability Detail

CVE-2026-64900UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office SharePoint XSS Spoofing

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft SharePoint Enterprise Server 2016
Attack Type
Spoofing
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-08-11T17:18:50.827Z",
  "pubdate": "2026-08-11T17:18:50.827Z",
  "executiveSummary": "A cross-site scripting (XSS) vulnerability exists within Microsoft Office SharePoint due to improper neutralization of user-supplied input during web page generation. This security flaw enables an authorized remote attacker to conduct spoofing attacks over the network against target environments. The primary impact of successful exploitation involves unauthorized content injection and potential manipulation of the user interface or session context within the affected web application. The vulnerability affects Microsoft Office SharePoint deployments and poses significant risk to data integrity and user trust within collaborative workspaces. Exploitation requires the attacker to have authorized access to the network and the application to inject malicious payloads that are subsequently rendered by the victim's browser. Although authorization is required, the capability allows malicious actors to leverage trusted application contexts to deceive users or execute arbitrary script logic within the scope of the victim's authenticated session. Organizations utilizing Microsoft Office SharePoint must prioritize remediation by applying vendor-supplied security updates and enforcing strict input validation and output encoding mechanisms to prevent script execution vectors.",
  "technicalDetails": "The vulnerability stems from improper neutralization of input during web page generation, specifically manifesting as a cross-site scripting (XSS) flaw in Microsoft Office SharePoint. The root cause lies in the application's failure to adequately sanitize, validate, or encode user-controlled data before reflecting it back within dynamically generated web pages. When input containing executable script tags or malicious event handlers is processed by the vulnerable component, the application incorporates the raw data directly into the Document Object Model (DOM) of the response without applying context-aware output encoding.\nExploitation occurs over the network and requires the attacker to be authorized within the SharePoint environment. To execute the attack, the adversary crafts a malicious payload containing specially formatted Hypertext Markup Language (HTML) or JavaScript constructs and submits this input to the vulnerable application endpoint through standard data entry vectors, list items, or web parts. Once the input is stored or reflected by the server, the vulnerable web page is served to other users accessing the SharePoint site.\nUpon receiving the malicious HTTP response, the victim's web browser parses the incoming document and executes the injected script within the security context of the vulnerable origin. Because the script executes in the user's browser session, it can inherit the user's privileges, access session tokens, manipulate page content to display deceptive spoofed interfaces, or perform unauthorized actions on behalf of the victim. The attack flow relies entirely on the browser's inability to differentiate between legitimate application code and injected malicious payloads due to the lack of proper neutralization on the server side.\nThe affected component is the web page generation mechanism of Microsoft Office SharePoint. The privilege requirements dictate that the threat actor must possess valid authorization to interact with the application and submit inputs that get reflected or stored. The attack vector is strictly network-based, allowing remote exploitation provided network connectivity to the SharePoint server is established."
}
CVE-2026-64900: Microsoft Office SharePoint XSS Spoofing (HIGH Severity, CVSS: 7.3) - Sceawere