CVE-2026-70355
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
In plain language
AI Act nowCVE-2026-70355 is a SharePoint security flaw where a user with low-level access can use crafted web input to run malicious scripts and gain higher permissions; RED—this is worth acting on if your SharePoint is exposed and attackers could obtain a basic account.
CVE-2026-70355 is a cross-site scripting (CWE-79) issue in Microsoft SharePoint Server that can be triggered through unsanitized web inputs by an authenticated attacker (with low-level credentials) and requires user interaction, enabling elevation of privileges within the SharePoint environment.
What to do now
- Check whether you run Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, or SharePoint Server, and note the current SharePoint build/patch level.
- If you are on Microsoft SharePoint Server 2019, upgrade SharePoint to 16.0.10417.20198 or later.
- If you are on Microsoft SharePoint Server Subscription Edition or SharePoint Server, upgrade SharePoint to 16.0.19725.20522 or later.
- Review who has low-level SharePoint credentials and reduce unnecessary access (especially accounts that can interact with pages/views that accept web input).
- After upgrading, watch SharePoint logs for unusual scripted-content activity and privilege changes around the time of the upgrade.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-70355 and every CVE in our database. Create a free account — no credit card required.
Create Free Account