CVE-2026-20958
vulnerability analysis and mitigation

Overview

CVE-2026-20958 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft Office SharePoint that allows an authenticated attacker to disclose information over a network. It was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday update. Affected products include Microsoft SharePoint Server 2016 Enterprise (below 16.0.5535.1001), SharePoint Server 2019 (below 16.0.10417.20083), and SharePoint Server Subscription Edition (below 16.0.19127.20442). The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Microsoft MSRC, Feedly).

Technical details

The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where SharePoint Server fails to adequately validate or restrict URLs supplied by an authenticated user, allowing the server to be coerced into making requests to internal or otherwise restricted network resources. An attacker with low-privilege authenticated access can craft malicious requests that cause the SharePoint server to fetch internal resources, potentially exposing sensitive network-level information. No user interaction is required, and the attack is conducted entirely over the network (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in limited information disclosure and minor integrity impact, with no availability impact. An authenticated attacker could leverage the SSRF to probe internal network services, access metadata endpoints, or retrieve sensitive data from internal resources that the SharePoint server can reach but the attacker cannot directly access. The scope is unchanged, meaning the impact is confined to the SharePoint server's network context rather than enabling broader lateral movement (Microsoft MSRC, Feedly).

Mitigation and workarounds

Microsoft released security updates on January 13, 2026, addressing this vulnerability. Organizations should update to the following patched versions or later: SharePoint Server 2019 to version 16.0.10417.20083 or above, SharePoint Server 2016 Enterprise to version 16.0.5535.1001 or above, and SharePoint Server Subscription Edition to version 16.0.19127.20442 or above. Given the medium severity rating and authentication requirement, patching within standard maintenance windows after internal testing is appropriate (Microsoft MSRC, Feedly).

Community reactions

CVE-2026-20958 was covered as part of broader January 2026 Patch Tuesday roundups by several security outlets. Zero Day Initiative reviewed the January 2026 update release, and BleepingComputer reported on the full patch batch of 114 flaws (ZDI Blog, BleepingComputer). Sophos and Lansweeper also published Patch Tuesday summaries that included this CVE among the broader set of SharePoint fixes. No specific researcher commentary or significant community discussion focused on this individual vulnerability was observed, consistent with its medium severity and lack of public exploitation.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management