SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-69636

MEDIUM · CVSS 6.5 EPSS 0.95%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Microsoft SharePoint and Office are vulnerable to SQL injection due to improper handling of special elements in SQL commands, allowing authorized attackers to potentially disclose sensitive information over the network. Organizations using these products should prioritize addressing this vulnerability to mitigate the risk of data exposure. This is particularly critical for environments where sensitive data is managed or shared.

CVE
CVE-2026-69636
Severity
MEDIUM
CVSS
6.5
EPSS
0.95%
Microsoft SharePoint Office

Original NVD Description

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)