CVE-2026-69716Important
Microsoft Office SharePoint Elevation of Privilege Vulnerability
Assessment
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- Severity
- Important
- CVSS base score
- 8.8CVSS:3.1/
AV:N/ AC:L/ PR:L/ UI:N/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Elevation of Privilege
- EPSS, next 30 days
- 1.0%Higher than 60.9% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Microsoft Office SharePoint
- Weakness
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Issued by
- Microsoft
- Published
- 8 Sep 2026 · September 2026
- Last revised
- 8 Sep 2026
Updates that fix it
1 KB| KB | Type | Restart | Applies to | Other CVEs |
|---|---|---|---|---|
| KB5002908 | Security Update | — | Microsoft SharePoint Server Subscription Edition | All CVEs in KB5002908 |
Affected products
Microsoft Office1 affected product
- Microsoft SharePoint Server Subscription Edition