CVE-2026-20947
EUVD-2026-211913.01.2026, 18:16
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| microsoft | sharepoint_server | 𝑥 < 16.0.19127.20442 |
𝑥
= Vulnerable software versions