CVE-2026-58639
Microsoft SharePoint Server Spoofing Vulnerability
Description
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
In plain language
AI Act nowCVE-2026-58639 is a SharePoint bug where a basic authenticated user can trick the server into making “pretend” requests to hidden internal systems, which can enable impersonation inside your network; if you have any user accounts or integrations that could be abused, you should act urgently.
CVE-2026-58639 is an authenticated SSRF/spoofing weakness (CWE-918) in Microsoft SharePoint Server components that lets a low-privileged attacker craft requests causing the server to fetch data from hidden internal locations, enabling impersonation/spoofing within the private network without server takeover.
What to do now
- Check whether you run Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition (sharepoint server), and note your current build/version.
- Compare your current SharePoint version against the fixed versions below and confirm whether you’re already on a fixed build.
- If not fixed, upgrade/apply the Microsoft patch for CVE-2026-58639 to the matching fixed build: Enterprise Server 2016 → 16.0.5565.1001; Server 2019 → 16.0.10417.20198; Subscription Edition → 16.0.19725.20522.
- Reduce the risk of account abuse by reviewing and limiting who has low-privileged access to SharePoint and related app permissions.
- After patching, review SharePoint/server logs for unusual outbound/internal fetch patterns associated with spoofing behavior and investigate any suspicious activity around the time of attempts.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-58639 and every CVE in our database. Create a free account — no credit card required.
Create Free Account