[WID-SEC-2026-2691] Microsoft SharePoint Online: Schwachstelle ermöglicht Cross-Site Scripting CVSS Base Score 9.6 (kritisch) CVSS Temporal Score 8.3 (hoch) Remoteangriff ja Datum 06.08.2026 Stand 07.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Windows Produktbeschreibung Microsoft Sharepoint Services ist ein Portalsystem für die zentrale Verwaltung von Dokumenten und Anwendungen. Die Inhalte werden u.a. über Webseiten zur Verfügung gestellt. Produkte 06.08.2026 Microsoft SharePoint Online Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Microsoft SharePoint Online ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A critical (CVSS 9.6) Cross-Site Scripting vulnerability in Microsoft SharePoint Online allows a remote, anonymous attacker to execute arbitrary script in a victim's browser context. The advisory indicates a mitigation is available, but specific affected version ranges and a fixed version number are not provided in the source text.