Improper input validation in Microsoft SharePoint Server (CVE-2026-32201) — risk of spoofing over a network
Microsoft SharePoint Server, an enterprise information-sharing platform, contains an improper input validation flaw (CWE-20). An attacker may perform spoofing over a network. NVD's Primary assessment is CVSS 6.5 (MEDIUM). CISA added it to the KEV on 2026-04-14, due 2026-04-28.
Key facts
- CVE IDCVE-2026-32201
- CVSS base score6.5 MEDIUM
- CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Affected (vendor / product)Microsoft SharePoint Server
- CWECWE-20
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-04-28 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Improper input validation (CWE-20) in Microsoft SharePoint Server — risk of spoofing over a network.
- NVD's Primary assessment is CVSS 6.5 (MEDIUM; C:L/I:L — limited impact to confidentiality/integrity).
- SharePoint is an enterprise document-sharing and intranet-portal platform where sensitive information gathers.
- Spoofing is a foothold for information theft or unauthorized operations — widening damage combined with other attacks.
- CISA added it to the KEV on 2026-04-14 (due 2026-04-28) = exploited even at MEDIUM.
"Spoofing" is an attack in which an attacker impersonates another legitimate entity (a user or server) to deceive the other party. This flaw stems from insufficient input validation in Microsoft SharePoint Server, said to let an unauthorized attacker perform such spoofing over a network.
SharePoint is widely used as an enterprise document-sharing and intranet-portal platform where much sensitive information gathers, so spoofing can be a foothold for information theft or unauthorized operations.
NVD's Primary assessment is CVSS 6.5 (MEDIUM), with limited impact to confidentiality and integrity (C:L/I:L). It is not a direct takeover like remote code execution, but spoofing can widen damage when combined with other attacks. SharePoint has had multiple vulnerabilities exploited in the past, and this joined the KEV as one of them.
The number is MEDIUM, but CISA's addition to the KEV shows this flaw is being used in real attacks. Weaknesses in a widely used information platform become real targets regardless of a high or low CVSS. The response is prompt updating per Microsoft's guidance.
Why it matters
SharePoint is an enterprise document-sharing and intranet platform where sensitive information gathers. Spoofing is not a direct takeover, but can widen damage through information theft or combination with other attacks. NVD's Primary assessment is MEDIUM (6.5), but being on the KEV means actual exploitation; weaknesses in a widely used information platform become targets regardless of the score. Prompt updating per Microsoft's guidance is the key point.
FAQ
What is spoofing?
Why act if the CVSS is only MEDIUM?
Is this the same as the earlier SharePoint flaw?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).