CVE-2026-65660: a SharePoint code injection reachable with an ordinary user account

CVE-2026-65660: a SharePoint code injection reachable with an ordinary user account

CVE-2026-65660:一个可通过普通用户账户利用的 SharePoint 代码注入漏洞

CVE-2026-65660: a SharePoint code injection reachable with an ordinary user account SharePoint is rarely treated as a perimeter system, which is why a flaw in it reads as lower priority than an edge appliance. CVE-2026-65660 changes that calculus. The vulnerability is a code injection in Microsoft SharePoint Server, added to the KEV catalog after exploitation was observed, and it is reachable by an authenticated user with low privileges. CVE-2026-65660:一个可通过普通用户账户利用的 SharePoint 代码注入漏洞。SharePoint 很少被视为边界系统,这就是为什么其漏洞的优先级通常被认为低于边缘设备。CVE-2026-65660 改变了这一评估。该漏洞是 Microsoft SharePoint Server 中的一个代码注入漏洞,在观察到实际利用后已被加入 KEV(已知被利用漏洞)目录,且低权限的已认证用户即可利用该漏洞。

What the flaw is The vulnerability is a code injection in SharePoint Server. The distinction from a remote unauthenticated flaw is important: the attacker needs an account, which means the entry point is more likely to be a phished credential, a contractor account, or a service account that was left with interactive access than a mass scanning campaign. 漏洞详情:该漏洞是 SharePoint Server 中的一个代码注入漏洞。它与远程未授权漏洞的区别非常重要:攻击者需要一个账户,这意味着其切入点更有可能是通过钓鱼获取的凭据、承包商账户,或是被保留了交互式访问权限的服务账户,而非大规模的扫描攻击。

Why an authenticated flaw is still a serious one An attacker with a valid low-privilege account already has what a scanner does not: a legitimate session, a valid audit trail, and the ability to reach internal resources that are not exposed to the internet. In a document management platform the account can create content, and content is processed by other users and by server-side components. Detection also suffers. Requests from an authenticated user sit inside normal traffic, so the signal is behavioural rather than structural. A spike in requests to server-side component paths from one account, or requests that arrive outside that account’s normal working pattern, is closer to what an investigation can actually use. 为什么已认证漏洞依然严重:拥有有效低权限账户的攻击者具备扫描器所没有的优势:合法的会话、有效的审计追踪,以及访问未暴露在互联网上的内部资源的能力。在文档管理平台中,该账户可以创建内容,而这些内容会被其他用户和服务器端组件处理。这也增加了检测难度。来自已认证用户的请求隐藏在正常流量中,因此其特征更多表现为行为异常而非结构异常。针对服务器端组件路径的请求激增,或请求出现在该账户正常工作模式之外,这些才是调查中更具参考价值的线索。

Why document platforms keep producing injection bugs A collaboration platform is a set of server-side renderers, converters and web parts assembled over many years, and each of them accepts structured input. Code injection tends to appear where a component builds executable content from data that a user supplied, and where the boundary between data and code is defined by convention rather than enforced by the runtime. 为什么文档平台频发注入漏洞:协作平台是由多年积累的服务器端渲染器、转换器和 Web 部件组成的集合,每一个组件都会接收结构化输入。当组件使用用户提供的数据构建可执行内容,且数据与代码之间的界限仅由约定定义而非由运行时强制执行时,代码注入漏洞往往就会出现。

What to do Apply Microsoft’s updates for the affected SharePoint Server versions. Confirm which farms are still in scope, since SharePoint estates commonly include older farms that were kept for a single application. Given confirmed exploitation, presume the entry point was a real account and review it. Look at authentication events for accounts with privileges well beyond their role, at new site collections and web parts created recently, and at outbound connections from SharePoint servers to destinations that are not part of normal integration traffic. 应对措施:为受影响的 SharePoint Server 版本应用 Microsoft 的更新。确认哪些服务器场(farms)仍在范围内,因为 SharePoint 环境通常包含为了单一应用而保留的旧服务器场。鉴于漏洞已被确认利用,应假设切入点是一个真实账户并进行审查。检查那些权限远超其职责范围的账户的认证事件,查看近期创建的新网站集和 Web 部件,并监控从 SharePoint 服务器发出的、不属于正常集成流量的外部连接。

References iThome weekly security roundup, 2 October 2026, https://www.ithome.com.tw/news/179381 Daily security intelligence report, 1 October 2026, https://blog.csdn.net/weixin_45635831/article/details/166945207 参考资料:iThome 每周安全综述,2026 年 10 月 2 日,https://www.ithome.com.tw/news/179381;每日安全情报报告,2026 年 10 月 1 日,https://blog.csdn.net/weixin_45635831/article/details/166945207