Sceawere
Vulnerability Detail
CVE-2026-65660UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SharePoint Code Injection Spoofing Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 7h ago
- Vendor
- Microsoft
- Product
- Microsoft SharePoint Enterprise Server 2016
- Attack Type
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-08-11T17:18:54.080Z",
"pubdate": "2026-08-11T17:18:54.080Z",
"executiveSummary": "A code injection vulnerability categorized under improper control of generation of code exists within Microsoft Office SharePoint. This security flaw enables an authorized threat actor to execute spoofing attacks over a network.\nThe vulnerability directly impacts Microsoft Office SharePoint deployments. Risk implications include the potential compromise of system integrity and the ability for malicious actors to masquerade as legitimate entities or execute unauthorized instructions within the application context.\nExploitation of this flaw requires the attacker to possess a baseline level of authorization within the environment and network connectivity to the target SharePoint infrastructure.\nThe inherent risk involves the unauthorized generation and execution of code, leading to compromised trust boundaries and potential unauthorized actions executed across the network.",
"technicalDetails": "The root cause of the vulnerability stems from improper control of generation of code, specifically classified as code injection, within the Microsoft Office SharePoint architecture.\nThe vulnerability is exposed over a network vector, allowing network-adjacent or remote authenticated attackers to interact with vulnerable components.\nAuthentication requirements dictate that the attacking entity must be an authorized user to initiate the attack sequence.\nPrivilege requirements involve having sufficient access permissions to supply input that the SharePoint application improperly processes and translates into executable or dynamic code constructs.\nThe attack flow proceeds as follows: First, the authorized attacker crafts a malicious input sequence designed to exploit the improper code generation handling within the vulnerable component of Microsoft Office SharePoint. Second, the attacker transmits this payload over the network to the target system. Third, the SharePoint application processes the input without adequate sanitization or structural validation. Fourth, the flawed logic results in the unintended generation and execution of injected code constructs.\nThe payload behavior leverages the application's internal code generation mechanisms to manipulate the execution flow or application output. The post-exploitation impact includes the execution of spoofing maneuvers over the network, undermining the authenticity and integrity of system interactions and communications."
}