
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20958 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft Office SharePoint that allows an authenticated attacker to disclose information over a network. It was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday update. Affected products include Microsoft SharePoint Server 2016 Enterprise (below 16.0.5535.1001), SharePoint Server 2019 (below 16.0.10417.20083), and SharePoint Server Subscription Edition (below 16.0.19127.20442). The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where SharePoint Server fails to adequately validate or restrict URLs supplied by an authenticated user, allowing the server to be coerced into making requests to internal or otherwise restricted network resources. An attacker with low-privilege authenticated access can craft malicious requests that cause the SharePoint server to fetch internal resources, potentially exposing sensitive network-level information. No user interaction is required, and the attack is conducted entirely over the network (Microsoft MSRC, Feedly).
Successful exploitation results in limited information disclosure and minor integrity impact, with no availability impact. An authenticated attacker could leverage the SSRF to probe internal network services, access metadata endpoints, or retrieve sensitive data from internal resources that the SharePoint server can reach but the attacker cannot directly access. The scope is unchanged, meaning the impact is confined to the SharePoint server's network context rather than enabling broader lateral movement (Microsoft MSRC, Feedly).
Microsoft released security updates on January 13, 2026, addressing this vulnerability. Organizations should update to the following patched versions or later: SharePoint Server 2019 to version 16.0.10417.20083 or above, SharePoint Server 2016 Enterprise to version 16.0.5535.1001 or above, and SharePoint Server Subscription Edition to version 16.0.19127.20442 or above. Given the medium severity rating and authentication requirement, patching within standard maintenance windows after internal testing is appropriate (Microsoft MSRC, Feedly).
CVE-2026-20958 was covered as part of broader January 2026 Patch Tuesday roundups by several security outlets. Zero Day Initiative reviewed the January 2026 update release, and BleepingComputer reported on the full patch batch of 114 flaws (ZDI Blog, BleepingComputer). Sophos and Lansweeper also published Patch Tuesday summaries that included this CVE among the broader set of SharePoint fixes. No specific researcher commentary or significant community discussion focused on this individual vulnerability was observed, consistent with its medium severity and lack of public exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."