CVE-2026-69716
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- CWE
- CWE-89
- Published
- 2026-09-08
- Last modified
- 2026-09-09
Affected products
- Microsoft Microsoft SharePoint Server Subscription Edition
Weakness type
Related vulnerabilities
- CVE-2026-79640 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-80177 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-19778 — WPMR Google Feed Manager for WooCommerce <= 2.23.7 - Authenticated (Administrator+) SQL Injection via 'feed' Parameter
- CVE-2026-19944 — WP Crowdfunding <= 2.2.1 - Authenticated (Shop Manager+) SQL Injection via 'wpneo_reward' Post Meta
- CVE-2026-19800 — Mail Mint <= 1.31.0 - Authenticated (Custom+) SQL Injection via 'status' Parameter
- CVE-2026-87034 — Tanium addressed a SQL injection vulnerability in Comply.
- CVE-2026-78623 — Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datastores
- CVE-2026-75746 — ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)