DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

CVE-2026-65660: a SharePoint code injection reachable with an ordinary user account

CVE-2026-65660: a SharePoint code injection reachable with an ordinary user account

SharePoint is rarely treated as a perimeter system, which is why a flaw in it reads as lower priority than an edge appliance. CVE-2026-65660 changes that calculus. The vulnerability is a code injection in Microsoft SharePoint Server, added to the KEV catalog after exploitation was observed, and it is reachable by an authenticated user with low privileges.

What the flaw is

The vulnerability is a code injection in SharePoint Server. The distinction from a remote unauthenticated flaw is important: the attacker needs an account, which means the entry point is more likely to be a phished credential, a contractor account, or a service account that was left with interactive access than a mass scanning campaign.

Why an authenticated flaw is still a serious one

An attacker with a valid low-privilege account already has what a scanner does not: a legitimate session, a valid audit trail, and the ability to reach internal resources that are not exposed to the internet. In a document management platform the account can create content, and content is processed by other users and by server-side components.
Detection also suffers. Requests from an authenticated user sit inside normal traffic, so the signal is behavioural rather than structural. A spike in requests to server-side component paths from one account, or requests that arrive outside that account's normal working pattern, is closer to what an investigation can actually use.

Why document platforms keep producing injection bugs

A collaboration platform is a set of server-side renderers, converters and web parts assembled over many years, and each of them accepts structured input. Code injection tends to appear where a component builds executable content from data that a user supplied, and where the boundary between data and code is defined by convention rather than enforced by the runtime.

What to do

Apply Microsoft's updates for the affected SharePoint Server versions. Confirm which farms are still in scope, since SharePoint estates commonly include older farms that were kept for a single application.
Given confirmed exploitation, presume the entry point was a real account and review it. Look at authentication events for accounts with privileges well beyond their role, at new site collections and web parts created recently, and at outbound connections from SharePoint servers to destinations that are not part of normal integration traffic.

References

Top comments (0)