CVE-2026-69716
Microsoft · Published September 8, 2026
8.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Microsoft Office SharePoint Elevation of Privilege Vulnerability. Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Affected Products
- Microsoft SharePoint Server Subscription Edition
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C