DEV Community
Follow
CVE-2026-65660: a SharePoint code injection reachable with an ordinary user account
A newly identified vulnerability in Microsoft SharePoint Server, CVE-2026-65660, is now considered a significant threat. This code injection flaw is particularly concerning because it has been observed being exploited in the wild and added to the KEV catalog. Importantly, the vulnerability requires an authenticated user with low privileges to exploit. This means an attacker would likely need compromised credentials, such as from phishing or an insecure service account.An authenticated attacker bypasses initial network defenses and already possesses a legitimate session and access to internal resources. Within a document management system like SharePoint, such an account can create content, which is then processed by other users and server components. Detecting this type of attack is more challenging as malicious activity blends into normal authenticated user traffic. Investigations must rely on behavioral anomalies rather than structural deviations.Code injection bugs persist in document platforms due to their complex architecture, built over time with various components that process user-supplied structured input. The vulnerability arises when components construct executable content from data without strict runtime enforcement separating data from code. To mitigate this risk, organizations must immediately apply Microsoft's security updates for affected SharePoint Server versions. It is also crucial to identify and assess all SharePoint farms, especially older ones that might still be in use.Given the confirmed exploitation, it's essential to investigate potential entry points, assuming a real account was compromised. This involves reviewing authentication logs for privilege misuse, newly created site collections or web parts, and unusual outbound network connections from SharePoint servers. Such proactive measures are vital to contain the impact of this serious vulnerability.