VDB
GCVE-110-NCSC-2026-237
GCVE-110-NCSC-2026-237
Advisory PublishedCVSS 6.5/10
An external control of file name or path vulnerability in Microsoft Office SharePoint allows an authorized attacker to perform network spoofing.
Weaknesses (CWE)
CWE-73External Control of File Name or PathCWE-306Missing Authentication for Critical FunctionCWE-502Deserialization of Untrusted DataCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-125Out-of-bounds ReadCWE-122Heap-based Buffer OverflowCWE-190Integer Overflow or WraparoundCWE-416Use After FreeCWE-1287Improper Validation of Specified Type of InputCWE-121Stack-based Buffer OverflowCWE-415Double FreeCWE-918Server-Side Request Forgery (SSRF)CWE-1390Weak AuthenticationCWE-197Numeric Truncation ErrorCWE-862Missing AuthorizationCWE-822Untrusted Pointer DereferenceCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-126Buffer Over-readCWE-908Use of Uninitialized Resource
Risk Scores
CVSS 3.1
6.5/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | vers:unknown/* | — | — |
Aliases
CVE-2026-47290CVE-2026-47642CVE-2026-48580CVE-2026-50301CVE-2026-50314CVE-2026-50387CVE-2026-50408CVE-2026-50467CVE-2026-50522CVE-2026-50665CVE-2026-50675CVE-2026-50678CVE-2026-54108CVE-2026-54131CVE-2026-54988CVE-2026-55016CVE-2026-55017CVE-2026-55018CVE-2026-55019CVE-2026-55020CVE-2026-55021CVE-2026-55022CVE-2026-55023CVE-2026-55024CVE-2026-55025CVE-2026-55026CVE-2026-55027CVE-2026-55028CVE-2026-55029CVE-2026-55030CVE-2026-55031CVE-2026-55032CVE-2026-55033CVE-2026-55034CVE-2026-55035CVE-2026-55036CVE-2026-55037CVE-2026-55038CVE-2026-55039CVE-2026-55040CVE-2026-55041CVE-2026-55042CVE-2026-55043CVE-2026-55044CVE-2026-55045CVE-2026-55046CVE-2026-55047CVE-2026-55048CVE-2026-55049CVE-2026-55050CVE-2026-55051CVE-2026-55052CVE-2026-55053CVE-2026-55054CVE-2026-55055CVE-2026-55056CVE-2026-55057CVE-2026-55058CVE-2026-55120CVE-2026-55122CVE-2026-55123CVE-2026-55124CVE-2026-55125CVE-2026-55126CVE-2026-55127CVE-2026-55128CVE-2026-55129CVE-2026-55130CVE-2026-55131CVE-2026-55132CVE-2026-55133CVE-2026-55134CVE-2026-55135CVE-2026-55136CVE-2026-55137CVE-2026-55138CVE-2026-55139CVE-2026-55140CVE-2026-55141CVE-2026-55142CVE-2026-55898CVE-2026-55899CVE-2026-55947CVE-2026-55948CVE-2026-55949CVE-2026-56156CVE-2026-56157CVE-2026-56164CVE-2026-56192CVE-2026-56193CVE-2026-56195CVE-2026-58277CVE-2026-58618CVE-2026-58644
References
Browse GCVE Records
75,792 records in the GCVE database · Updated August 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.