CVE-2026-20947 is a critical SQL injection vulnerability affecting Microsoft Office SharePoint Server. An authenticated attacker can exploit this flaw over a network to achieve remote code execution. This vulnerability carries a high CVSS score of 8.8, indicating a low attack complexity and significant potential for high impact on confidentiality, integrity, and availability. While there is no public exploit code or evidence of active exploitation, the vulnerability has garnered substantial community discussion and media coverage, suggesting heightened awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.0.19127.20442CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.