AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-70355

HIGH · CVSS 7.3 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Microsoft Office SharePoint is vulnerable due to improper input neutralization during web page generation, leading to a cross-site scripting (XSS) vulnerability. This flaw allows an authorized attacker to execute scripts in the context of another user, potentially elevating their privileges and compromising sensitive data. Organizations using SharePoint should prioritize patching this vulnerability to mitigate the risk of unauthorized access and data breaches.

CVE
CVE-2026-70355
Severity
HIGH
CVSS
7.3
EPSS
0.42%
Microsoft SharePoint Office

Original NVD Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)