PT-2026-60599 · Microsoft · Sharepoint Server
CVE-2026-62826
·
Published
2026-07-14
·
Updated
2026-07-22
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft SharePoint Server (affected versions not specified)
Microsoft SharePoint Server Subscription Edition (affected versions not specified)
Microsoft SharePoint Enterprise Server 2016
Description
An issue exists due to improper neutralization of input during web page generation, leading to cross-site scripting (XSS). This allows an authorized remote attacker to perform spoofing by executing attacker-controlled scripts within a user's browser.
Recommendations
Upgrade Microsoft SharePoint Enterprise Server 2016 to a vendor-listed fixed release.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for Microsoft SharePoint Server and Microsoft SharePoint Server Subscription Edition.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sharepoint Server