Sceawere

Vulnerability Detail

CVE-2026-70324UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office SharePoint SSRF Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft SharePoint Enterprise Server 2016
Attack Type
CWE-918: Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-11T17:19:10.143Z",
  "pubdate": "2026-08-11T17:19:10.143Z",
  "executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in Microsoft Office SharePoint, enabling an authorized attacker to achieve privilege escalation over a network.\nThe vulnerability allows malicious actors to manipulate SharePoint server functionality to initiate unauthorized outbound requests to arbitrary internal or external endpoints.\nAffected systems include Microsoft Office SharePoint Server deployments. The primary risk implication involves unauthorized access to backend resources and subsequent elevation of privileges within the network boundary.\nTo successfully exploit this security flaw, an attacker must possess authenticated access to the target SharePoint environment and the ability to interact with vulnerable server-side components over the network.\nThe flaw compromises the trust boundaries of the application server, allowing attackers to leverage the host server's network positioning to interact with restricted services.",
  "technicalDetails": "The vulnerability stems from improper input validation and sanitization of user-supplied URLs or network routing parameters within server-side request handling routines in Microsoft Office SharePoint.\nThe vulnerable component processes external resource fetches without adequately restricting destination IP addresses, enabling the abuse of network communication protocols such as HTTP, HTTPS, or internal service channels.\nAuthentication requirements dictate that the attacker must be an authorized user within the SharePoint domain, possessing baseline privileges necessary to access the specific vulnerable functionality or interface.\nThe network exposure is restricted to the internal network or the perimeter boundary, contingent upon the SharePoint deployment configuration and external accessibility.\nDuring the attack flow, the attacker submits a specially crafted payload containing malicious uniform resource identifiers targeting internal services, metadata endpoints, or ancillary infrastructure inaccessible from the external perimeter.\nUpon receiving the payload, the SharePoint server fails to validate the destination, subsequently executing the outbound request on behalf of the attacker.\nThe payload behavior leverages the server's elevated network context to bypass perimeter firewalls and network access control lists.\nPost-exploitation impact includes the potential retrieval of sensitive internal data, interaction with local administrative interfaces, and subsequent privilege escalation by exploiting secondary trust relationships or internal vulnerabilities exposed via the SSRF vector."
}
CVE-2026-70324: Microsoft Office SharePoint SSRF Privilege Escalation (HIGH Severity, CVSS: 8.8) - Sceawere