CVE-2026-48560
EUVD-2026-3558309.06.2026, 17:17
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| microsoft | sharepoint_server | 𝑥 < 16.0.19725.20384 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-502 - Deserialization of Untrusted DataThe application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.