CVE-2026-56157
Analyzed Analyzed - Analysis Complete

Improper Access Control in Microsoft Office SharePoint Allows Spoofing

Vulnerability report for CVE-2026-56157, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-15

Assigner: Microsoft Corporation

Description

Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-15
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
microsoft sharepoint_server 2019
microsoft sharepoint_server 2016
microsoft sharepoint_server to 16.0.19725.20434 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-56157 is a vulnerability in Microsoft Office SharePoint that involves improper access control. This flaw allows an authorized attacker to perform spoofing over a network. Spoofing in this context means the attacker can impersonate another user or system, potentially leading to unauthorized actions or data access.

The vulnerability is classified with a CVSS v3.1 base score of 5.4, indicating a medium severity level. The vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N means the attack can be executed over a network with low attack complexity, requires low privileges, and does not need user interaction. It can result in low confidentiality and integrity impacts but no availability impact.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying CVE-2026-56157 on a network or system. Detection typically involves checking SharePoint server logs, access control configurations, or using security tools that monitor for unauthorized access or spoofing attempts.

For precise detection steps, refer to Microsoft's official guidance or security advisories, which may include recommended tools or scripts.

Impact Analysis

If you are using Microsoft Office SharePoint, this vulnerability could allow an attacker with authorized access to impersonate other users or systems within your network. This could lead to several potential impacts:

  • Unauthorized access to sensitive data stored or managed in SharePoint.
  • Manipulation or alteration of data, leading to misinformation or fraudulent activities.
  • Potential reputational damage if attackers exploit the spoofing to perform malicious actions under the guise of legitimate users.

Since the vulnerability requires an attacker to already have some level of authorized access, the risk is higher in environments where user credentials or access controls are not strictly managed.

Compliance Impact

This vulnerability could impact compliance with several common standards and regulations, depending on the data and systems involved:

  • GDPR (General Data Protection Regulation): If SharePoint is used to store or process personal data of EU citizens, unauthorized access or spoofing could lead to data breaches. GDPR requires organizations to implement appropriate security measures to protect personal data, and failure to address this vulnerability could result in non-compliance and potential fines.
  • HIPAA (Health Insurance Portability and Accountability Act): If SharePoint is used in a healthcare setting to store or manage protected health information (PHI), this vulnerability could lead to unauthorized access or disclosure of PHI. HIPAA mandates strict access controls and safeguards, and exploiting this flaw could violate these requirements.
  • Other standards like ISO 27001 or NIST frameworks may also be affected, as they require organizations to maintain proper access controls and protect against unauthorized access or impersonation.

Organizations should assess whether their SharePoint deployment handles regulated data and take steps to mitigate this vulnerability to maintain compliance.

Mitigation Strategies

To mitigate CVE-2026-56157, follow these immediate steps:

  • Apply the latest security updates provided by Microsoft for Microsoft Office SharePoint. The patch for this vulnerability should be available via Microsoft's update channels.
  • Review and enforce strict access control policies for SharePoint environments to limit unauthorized access.
  • Monitor SharePoint logs for unusual activity or unauthorized access attempts that may indicate exploitation.
  • Restrict network access to SharePoint servers to trusted users and systems only, reducing the attack surface.

For detailed mitigation instructions, consult the official Microsoft advisory linked in Resource 1.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56157. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart