CVE-2026-54108 Details
Description
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
A spoofing vulnerability has been identified in Microsoft Office SharePoint, allowing an authorized attacker to manipulate file names or paths over the network. This issue affects multiple SharePoint products, including SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. The vulnerability arises from external control of file names or paths, which can be exploited to perform spoofing attacks.
Users can download the security update for Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 from the Microsoft Update Catalog. Specific KB articles for each SharePoint version are also available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54108 | [email protected] | Vendor AdvisoryPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-73 | External Control of File Name or Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft sharepoint server | < 16.0.19725.20434 2016 2019 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | Initial Analysis | [email protected] |
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |