CVE-2026-57105
Microsoft Office SharePoint Spoofing Vulnerability
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
In plain language
AI Act nowThis is a SharePoint security flaw where a logged-in attacker can trick other users’ browsers into running malicious code and impersonating trusted SharePoint content; if you allow user accounts and don’t keep SharePoint fully updated, it’s something you should act on now.
CVE-2026-57105 is a CWE-79 script injection (cross-site scripting) flaw in Microsoft SharePoint Server where an authenticated attacker can send a malicious payload over the network that gets executed in victims’ browsers, enabling spoofing of trusted content and potentially arbitrary actions within the browser/session.
What to do now
- Check your Microsoft SharePoint Server version for whether it is older than the fixed releases for your edition (SharePoint Server 2019 vs Subscription Edition).
- If you are on an affected version, plan and schedule an upgrade to the fixed version: SharePoint Server 2019 → 16.0.10417.20198, or Subscription Edition/sharepoint server → 16.0.19725.20522.
- After updating, verify SharePoint is serving the updated build and that web-facing pages reject/neutralize malicious input attempts (as validated by your security or QA process).
- If you cannot patch immediately, restrict who can access SharePoint accounts with the least privilege needed and reduce exposure of the SharePoint site to untrusted users while you prepare the upgrade.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-57105 and every CVE in our database. Create a free account — no credit card required.
Create Free Account