PT-2026-60599 · Microsoft · Sharepoint Server

CVE-2026-62826

·

Published

2026-07-14

·

Updated

2026-07-22

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Server (affected versions not specified) Microsoft SharePoint Server Subscription Edition (affected versions not specified) Microsoft SharePoint Enterprise Server 2016
Description An issue exists due to improper neutralization of input during web page generation, leading to cross-site scripting (XSS). This allows an authorized remote attacker to perform spoofing by executing attacker-controlled scripts within a user's browser.
Recommendations Upgrade Microsoft SharePoint Enterprise Server 2016 to a vendor-listed fixed release. At the moment, there is no information about a newer version that contains a fix for this vulnerability for Microsoft SharePoint Server and Microsoft SharePoint Server Subscription Edition.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10332
CVE-2026-62826

Affected Products

Sharepoint Server