CVE-2026-69636ImportantRevised 24 Sep
Microsoft Office SharePoint Information Disclosure Vulnerability
Assessment
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
- Severity
- Important
- CVSS base score
- 6.5CVSS:3.1/
AV:N/ AC:L/ PR:L/ UI:N/ S:U/ C:H/ I:N/ A:N/ E:U/ RL:O/ RC:C - Impact
- Information Disclosure
- EPSS, next 30 days
- 1.0%Higher than 61.2% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Microsoft Office SharePoint
- Weakness
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Issued by
- Microsoft
- Published
- 8 Sep 2026 · September 2026
- Last revised
- 24 Sep 2026Updated an acknowledgement. This is an informational change only.
Updates that fix it
1 KB| KB | Type | Restart | Applies to | Other CVEs |
|---|---|---|---|---|
| KB5002908 | Security Update | — | Microsoft SharePoint Server Subscription Edition | All CVEs in KB5002908 |
Affected products
Microsoft Office1 affected product
- Microsoft SharePoint Server Subscription Edition