HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-47634Published Modified CNA microsoft

CVE-2026-47634: Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Metrics

CVSS v3.1
7.3
Severity
HIGH
Fixed in
16.0.10417.20153
Affected Products
2

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A stored or reflected cross-site scripting (XSS) vulnerability exists in Microsoft SharePoint Server where user-supplied input is not properly sanitized before being rendered in web pages. The vulnerability is reachable over the network and requires a low-privilege authenticated account plus a victim clicking or visiting a crafted link or page. Successful exploitation allows an attacker to read sensitive data from the victim's browser session and tamper with page content, effectively impersonating the SharePoint interface to the victim. Patched-image rebuilds at versions 16.0.10417.20153 and 16.0.19725.20384 are available on HarborGuard for environments running affected versions.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against images in customer registries and CI/CD pipelines, including custom-built images that bundle SharePoint components. Any image containing an affected SharePoint version below the patched thresholds is flagged automatically.

Available
Triage

HarborGuard scores this CVE at CVSS 7.3 (High) using the published v3.1 vector and weights it further against each environment's active compliance policies before routing findings to the appropriate team inbox inside each customer organization.

Available
Patch

A patched-image rebuild at versions 16.0.10417.20153 (SharePoint Server 2019) and 16.0.19725.20384 (Subscription Edition) becomes available on HarborGuard once the upstream fix is resolved against an affected image. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the SharePoint Server over the network; the service must be exposed to the attacker's network segment or the internet.

  • AuthenticationRequired

    A low-privilege authenticated account is sufficient; anonymous access alone is not enough to trigger the vulnerability.

  • Victim interactionRequired

    A targeted user must interact with a crafted link or page, making this a social-engineering-dependent exploit.

  • Attack complexityDetail

    Exploit conditions are straightforward and require no race conditions or special environmental factors; the attack is reliable once the victim interacts.

Blast Radius

  • The attacker can read the victim's active SharePoint session tokens and any sensitive data rendered in the browser at the time of exploitation.
  • The attacker can inject and execute arbitrary scripts in the victim's browser, modifying displayed SharePoint page content to impersonate legitimate UI elements.
  • The attacker can perform actions on SharePoint on behalf of the victim, such as modifying or exfiltrating documents and list items the victim has access to.

How HarborGuard Handles This

Available on HarborGuard: detection against both affected SharePoint Server product lines is active from the moment the CVE enters upstream advisory feeds. Where compliance policy permits auto-remediation, HarborGuard rebuilds the image at the applicable fix version (16.0.10417.20153 for SharePoint Server 2019 or 16.0.19725.20384 for the Subscription Edition), runs a regression check, and opens a pull request against affected workloads. For environments with auto-remediation enabled, the median time from CVE publication to a merged patch PR for high-severity issues is around 90 minutes. For environments where auto-remediation is disabled or gated by an approval workflow, the finding is routed to the designated team inbox with fix-version details included so engineers can act without additional research.

See how HarborGuard automates this

Fix available

16.0.10417.2015316.0.19725.20384
Affected packages
  • Microsoft / Microsoft SharePoint Server 2019
    < 16.0.10417.20153 (from 16.0.0)
  • Microsoft / Microsoft SharePoint Server Subscription Edition
    < 16.0.19725.20384 (from 16.0.0)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C