Sceawere

Vulnerability Detail

CVE-2026-70306UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office SharePoint XSS Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft SharePoint Enterprise Server 2016
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-08-11T17:19:07.970Z",
  "pubdate": "2026-08-11T17:19:07.970Z",
  "executiveSummary": "This vulnerability involves an improper neutralization of input during web page generation, specifically categorized as cross-site scripting (XSS), affecting Microsoft Office SharePoint.\nThe primary impact of this security flaw is spoofing, allowing an unauthorized remote attacker to execute arbitrary scripts or manipulate content within the context of a victim's browser session.\nThe affected system is Microsoft Office SharePoint. The risk implications include potential session hijacking, unauthorized content injection, and the execution of malicious client-side logic against authenticated users interacting with the vulnerable web application.\nAn attacker must possess network access to the target SharePoint instance to successfully deliver the payload. Exploitation relies on the application's failure to adequately sanitize or encode user-supplied data before rendering it in web pages generated for users.\nNo advanced privileges or prior authentication are strictly required to initiate the attack vector, provided the input vector is accessible over the network to the unauthorized threat actor.",
  "technicalDetails": "The vulnerability is rooted in the insecure handling of user-supplied input by Microsoft Office SharePoint during the dynamic generation of web pages.\nSpecifically, the application suffers from improper input neutralization, which permits the injection of malicious scripts—typically JavaScript or HTML—into parameters or fields processed and rendered by the server without sufficient contextual output encoding.\nThe vulnerable component resides within the web application interface of Microsoft Office SharePoint, which processes and reflects HTTP requests or stored data directly to users' browsers.\nBecause the application fails to properly sanitize or escape input, a crafted payload can be successfully injected and subsequently executed within the security context of a victim's browser session.\nThe attack flow typically occurs via a network-based vector where an unauthorized attacker crafts a malicious request or URL containing the unneutralized payload.\nWhen a targeted user interacts with the crafted link or views the compromised web page generated by SharePoint, the browser parses and executes the injected script.\nThis payload execution can lead to spoofing conditions, session token theft, DOM manipulation, or the unauthorized execution of actions on behalf of the authenticated user.\nThe network exposure is remote, requiring network connectivity to the SharePoint server instances.\nAuthentication and privilege requirements for the attacker are minimal or absent depending on the specific injection surface, allowing unauthorized actors to leverage the weakness over the network."
}
CVE-2026-70306: Microsoft Office SharePoint XSS Vulnerability (CRITICAL Severity, CVSS: 9.3) - Sceawere