External risk intelligence

SharePoint Cross-Site Scripting Vulnerability Allows Spoofing

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-70306

Microsoft SharePoint is commonly deployed as an internet-facing web application, intranet portal, or collaborative service. Given its role as a web-based content management and collaboration platform, it is frequently exposed to network users or the public internet.

Cross-site Scripting

Microsoft Sharepoint Server

before 16.0.19725.2043420162019

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in Microsoft Office SharePoint that could allow an attacker to impersonate users and potentially steal sensitive information through crafted web pages. This issue matters because SharePoint is widely used for collaboration and document management, making it a valuable target for attackers seeking to disrupt operations or gain unauthorized access. The primary concern at this stage is to determine if your organization utilizes the affected technology and, if so, to assess the potential exposure.

  • Cross-site scripting allows website impersonation.
  • SharePoint is a common business collaboration tool.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could compromise a SharePoint server by crafting a malicious web page that, when viewed by a user, tricks the server into generating a response containing harmful code. This vulnerability allows an attacker to impersonate legitimate content or users, potentially leading to further compromise.

  • Requires network access to SharePoint.
  • User must view a crafted web page.
  • Leads to unauthorized spoofing.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to inject malicious scripts into web pages viewed by other users within a SharePoint environment, potentially leading to spoofing. When a user visits a compromised page, the injected script could execute in their browser, impersonating legitimate content or actions.

  • Web page content.
  • Via crafted web page input.
  • User actions may be spoofed.

Operational Fix

Recommended remediation, mitigation, and detection steps

This cross-site scripting vulnerability in Microsoft Office SharePoint requires immediate attention to identify affected systems and assess business criticality. Application owners and infrastructure teams should collaborate to locate all SharePoint instances, determine their exposure, and identify the accountable owner for each. A risk-based remediation plan, including potential vendor coordination and the scheduling of maintenance windows, should then be developed and executed.

  • Ownership lies with the SharePoint application or infrastructure team.
  • Verify external reachability and business criticality of instances.
  • Plan remediation based on confirmed exposure and risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Microsoft Office SharePoint?

Microsoft Office SharePoint is a web-based collaboration and document management platform. Organizations use it to store files, manage internal portals, and host websites that facilitate team communication and content sharing across a network.

What does CWE-79 mean in the context of CVE-2026-70306?

CWE-79 is classified as improper neutralization of input during web page generation, commonly known as Cross-Site Scripting (XSS). For this CVE, it means the application fails to properly filter malicious scripts from user-supplied data, allowing an attacker to execute unauthorized code within a victim's browser session.

How is this SharePoint vulnerability triggered?

An attacker triggers this bug by crafting a malicious web page that tricks the SharePoint server into including harmful script content. It does not trigger through standard document uploads or simple server access; the malicious input must be processed and subsequently viewed by an authenticated or targeted user within their browser.

Do I need to worry about this if my SharePoint is not on the public internet?

Halo Surface Signal notes that SharePoint is frequently deployed as an internet-facing service, but internal-only instances remain at risk. If your SharePoint environment is accessible to internal network users, an attacker who has gained a foothold on your internal network could still leverage this vulnerability to impersonate users.

When should I start addressing CVE-2026-70306?

You should prioritize addressing this vulnerability immediately by coordinating with your infrastructure and application teams. Start by creating a comprehensive inventory of all SharePoint instances to determine which are reachable by users, then assess the business criticality of those systems to schedule necessary updates or configuration changes.

References