Sceawere

Vulnerability Detail

CVE-2026-65660UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SharePoint Code Injection Spoofing Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft SharePoint Enterprise Server 2016
Attack Type
CWE-94: Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-11T17:18:54.080Z",
  "pubdate": "2026-08-11T17:18:54.080Z",
  "executiveSummary": "A code injection vulnerability categorized under improper control of generation of code exists within Microsoft Office SharePoint. This security flaw enables an authorized threat actor to execute spoofing attacks over a network.\nThe vulnerability directly impacts Microsoft Office SharePoint deployments. Risk implications include the potential compromise of system integrity and the ability for malicious actors to masquerade as legitimate entities or execute unauthorized instructions within the application context.\nExploitation of this flaw requires the attacker to possess a baseline level of authorization within the environment and network connectivity to the target SharePoint infrastructure.\nThe inherent risk involves the unauthorized generation and execution of code, leading to compromised trust boundaries and potential unauthorized actions executed across the network.",
  "technicalDetails": "The root cause of the vulnerability stems from improper control of generation of code, specifically classified as code injection, within the Microsoft Office SharePoint architecture.\nThe vulnerability is exposed over a network vector, allowing network-adjacent or remote authenticated attackers to interact with vulnerable components.\nAuthentication requirements dictate that the attacking entity must be an authorized user to initiate the attack sequence.\nPrivilege requirements involve having sufficient access permissions to supply input that the SharePoint application improperly processes and translates into executable or dynamic code constructs.\nThe attack flow proceeds as follows: First, the authorized attacker crafts a malicious input sequence designed to exploit the improper code generation handling within the vulnerable component of Microsoft Office SharePoint. Second, the attacker transmits this payload over the network to the target system. Third, the SharePoint application processes the input without adequate sanitization or structural validation. Fourth, the flawed logic results in the unintended generation and execution of injected code constructs.\nThe payload behavior leverages the application's internal code generation mechanisms to manipulate the execution flow or application output. The post-exploitation impact includes the execution of spoofing maneuvers over the network, undermining the authenticity and integrity of system interactions and communications."
}
CVE-2026-65660: SharePoint Code Injection Spoofing Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere