CyberRota Analysis
AI-GeneratedMicrosoft SharePoint and Office are vulnerable to SQL injection due to improper handling of special elements in SQL commands, allowing authorized attackers to potentially disclose sensitive information over the network. Organizations using these products should prioritize addressing this vulnerability to mitigate the risk of data exposure. This is particularly critical for environments where sensitive data is managed or shared.
CVE
CVE-2026-69636
Severity
MEDIUM
CVSS
6.5
EPSS
0.95%
Microsoft SharePoint Office
Original NVD Description
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Related CVEs
Other vulnerabilities affecting the same vendor(s)