CVE-2026-70306: Microsoft Office SharePoint Spoofing Vulnerability

Overview

Severity
Critical (CVSS 9.3)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Aug
Released
2026-08-11

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

FAQ

How could an attacker exploit this vulnerability? An attacker could send a specially crafted URL to an authenticated SharePoint user and persuade them to visit it and submit the form. Successful exploitation could allow the attacker to run script in the user's SharePoint session, potentially accessing information or modifying site content.

Affected Products (3)

Microsoft Office

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition

Security Updates (3)

Acknowledgments

Bui Xuan Quang (buxu) with Ncsgroup.vn, <a href="https://smlijun.github.io/">DongJun Kim</a> with UIUC, <a href="https://hwiwonl.ee/">Hwiwon Lee (hwiwonl)</a> with UIUC, <a href="https://nevul37.github.io/">Jongseong Kim (nevul37)</a> with UIUC

Revision History

  • 2026-08-11: Information published.