CVE-2026-69716: Microsoft Office SharePoint Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69716
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69716 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Microsoft Office SharePoint
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- lowCVE-2026-69904: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacke…nvd · 2026-09-08
- highCVE-2026-69804: Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an aut…nvd · 2026-09-08
- highCVE-2026-69724: Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute …nvd · 2026-09-08
- highCVE-2026-69716: Improper neutralization of special elements used in an sql command ('sql injection') in Micros…nvd · 2026-09-08
- mediumCVE-2026-69690: Improper neutralization of input during web page generation ('cross-site scripting') in Micros…nvd · 2026-09-08
- mediumCVE-2026-69683: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacke…nvd · 2026-09-08
More from Microsoft Security Response Center
- mediumCVE-2026-18924: HTTP/2 server push UAF2026-09-08
- highCVE-2026-69630: Windows Win32k Elevation of Privilege Vulnerability2026-09-08
- unknownCVE-2026-83616: xmldom: Processing Instruction Target Injection Bypasses requireWellFormed2026-09-08
- unknownCVE-2026-85062: Colord: Slow rejection of oversized malformed color strings2026-09-08
- mediumCVE-2026-80834: crypto: sun8i-ce - Remove crypto_rng interface2026-09-08