CVE-2026-69636: Microsoft Office SharePoint Information Disclosure Vulnerability

Overview

Severity
Medium (CVSS 6.5)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Sep
Released
2026-09-08
EPSS Score
0.95% (percentile: 59.2%)

Description

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

FAQ

What type of information could be disclosed by this vulnerability? An attacker could possibly gain access to an organizational's email, sites, filenames, or the URLs of files.

Affected Products (1)

Microsoft Office

  • Microsoft SharePoint Server Subscription Edition

Security Updates (1)

Acknowledgments

r0ser1, Cristian Chavez

Revision History

  • 2026-09-08: Information published.