
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26106 is a Remote Code Execution (RCE) vulnerability caused by improper input validation in Microsoft Office SharePoint. It affects Microsoft SharePoint Server 2016 (Enterprise, versions before 16.0.5543.1000), SharePoint Server 2019 (versions before 16.0.10417.20102), and SharePoint Server Subscription Edition (versions before 16.0.19725.20076). The vulnerability was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 8.8 (High), requiring only low privileges and no user interaction to exploit over the network (Microsoft MSRC, Feedly).
The root cause is classified as CWE-20 (Improper Input Validation) in Microsoft SharePoint Server's network-accessible components. An authenticated attacker with basic Site Member permissions can send specially crafted network requests that bypass input validation checks, triggering arbitrary code execution on the server. No user interaction is required, and the attack complexity is low, making this straightforward to exploit for any authenticated user. No public proof-of-concept or detailed technical write-up has been published as of the time of this report (Microsoft MSRC, Feedly).
Successful exploitation allows an authenticated attacker to execute arbitrary code remotely on the affected SharePoint Server, resulting in high impact to confidentiality, integrity, and availability. An attacker could gain unauthorized access to sensitive data stored in SharePoint, modify server configurations or content, disrupt service availability, and potentially use the compromised server as a pivot point for lateral movement within the organization's network. The low privilege requirement — only basic Site Member access — significantly lowers the barrier to exploitation, meaning any compromised or malicious insider account could achieve full server compromise (Feedly, Microsoft MSRC).
w3wp.exe spawning cmd.exe, powershell.exe, or other shells).Microsoft released security patches on March 10, 2026, addressing this vulnerability across all affected versions. Organizations should update to the following minimum versions immediately: SharePoint Server 2019 to 16.0.10417.20102 or later, SharePoint Server 2016 (Enterprise) to 16.0.5543.1000 or later, and SharePoint Server Subscription Edition to 16.0.19725.20076 or later. As interim measures, organizations should implement network segmentation to restrict SharePoint Server access to authorized personnel only, apply the principle of least privilege to limit user permissions, and monitor SharePoint logs for suspicious activity (Microsoft MSRC, Feedly).
CVE-2026-26106 was covered as part of broader March 2026 Patch Tuesday roundups by multiple security vendors and researchers, including Rapid7, Talos Intelligence, Zero Day Initiative (ZDI), Sophos, and Tenable, all noting the vulnerability's high CVSS score and low privilege requirement as notable risk factors (Rapid7, ZDI, Sophos, Talos). Community coverage highlighted the significance of the low privilege requirement as a key risk amplifier. No major controversy or exceptional researcher commentary specific to this CVE was noted beyond standard Patch Tuesday analysis.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."