CVE-2026-45454
Microsoft Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVSS
- 8.8
- EPSS
- 1.63% 73.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.10