Critical SharePoint On-Premises Flaw Lets Low‑Privilege Users Run Remote Code
Security researchers have identified a severe vulnerability in Microsoft SharePoint on-premises installations that enables authenticated users with minimal permissions to execute arbitrary code on the server, catalogued as CVE‑2026‑65660.
The issue, initially logged as a spoofing weakness, was found to allow crafted HTTP requests to bypass normal access controls and trigger remote code execution. The flaw resides in a component that processes user‑generated input, meaning an attacker does not need administrative rights to gain a foothold.
Enterprises that continue to host SharePoint on their own infrastructure are especially exposed. By leveraging a low‑privilege account, an adversary could potentially take full control of the SharePoint host, pivot to other systems, and harvest sensitive corporate data. The attack surface is broad because many organizations rely on on‑prem SharePoint for document management, intranet portals, and workflow automation.
The vulnerability was first disclosed by the independent security group GBHackers. Microsoft promptly assigned the CVE identifier and published an advisory outlining the technical details and the risk level. The advisory notes that the flaw is exploitable on any supported on‑premises version of SharePoint that has not been patched.
Microsoft’s response includes a security update that addresses the underlying code handling the malicious input. Administrators are urged to apply the patch without delay and to implement short‑term mitigations such as tightening network segmentation, enforcing strict least‑privilege policies, and disabling any unnecessary SharePoint services until the fix is in place.
Analysts caution that the window for exploitation remains open for organizations that have not yet updated. They recommend a thorough review of SharePoint deployments, continuous monitoring for anomalous activity, and, where feasible, a migration to cloud‑based SharePoint services that receive more frequent security updates. Prompt remediation will be essential to prevent attackers from turning a low‑privilege credential into a full server compromise.
Comments (0)
Be the first to comment.
Join the discussion