Abstract illustration of connected devices separated by a protected security boundary.
CVE-2026-69409, Microsoft Office SharePoint Information Disclosure Vulnerability, is an Important SharePoint Server flaw published on September 24, 2026 that can let an authorized network attacker access legal-hold and eDiscovery metadata beyond their permissions; administrators of Microsoft SharePoint Server Subscription Edition (x64) should install KB5002908 and confirm fixed build 16.0.20326.20090.

Microsoft assigns the vulnerability a 6.5 CVSS base score and a 5.7 temporal score. The practical risk is confidentiality: a user who already has valid authorization to reach the service may be able to obtain sensitive compliance-case information that SharePoint should withhold from that account. This is a patch-and-verify item for SharePoint administrators, particularly where legal discovery records carry sensitive case, employee, or investigation details.

CVE-2026-69409 stems from unnecessary SharePoint privileges​

Microsoft describes CVE-2026-69409 as “Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.” The weakness is classified as CWE-250, Execution with Unnecessary Privileges.

The full Microsoft title is Microsoft Office SharePoint Information Disclosure Vulnerability. Its CVSS v3.1 vector is:

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

In operational terms, the vector identifies a network-reachable issue with low attack complexity, but one requiring low privileges. No victim interaction is required. The score confines the listed technical impact to confidentiality: high confidentiality impact, with no integrity or availability impact represented in the vector.

Microsoft’s advisory is explicit about the kind of data at stake. Successful exploitation could disclose legal-hold and eDiscovery metadata an attacker is not authorized to view, including hold titles, descriptions, managers, and search criteria. This is metadata rather than a stated mechanism for changing records or taking a server offline, but it can reveal the subject, ownership, and scope of sensitive internal investigations or retention matters.

Publicly disclosed: No

Exploited: No

Customer action required: Yes

Microsoft’s exploitation assessment is Exploitation Less Likely. That assessment should inform patch prioritization, not replace it: the CVSS vector still describes an attack path available over the network to an authorized user.

KB5002908 fixes Microsoft SharePoint Server Subscription Edition (x64)​

The affected product named in the supplied Microsoft update mapping is Microsoft SharePoint Server Subscription Edition (x64). Microsoft maps the remedy to KB5002908, with fixed build 16.0.20326.20090.

The required remediation is exact:

For Microsoft SharePoint Server Subscription Edition (x64), install KB5002908 to reach fixed build 16.0.20326.20090.

For administrators, the important distinction is between deploying an update package and reaching the fixed build. A successful servicing workflow should include both installing KB5002908 and confirming that the relevant SharePoint Server Subscription Edition (x64) installation reaches build 16.0.20326.20090.

Microsoft also warns that some affected software can have multiple update packages listed in the Security Updates table. In those cases, customers should apply all updates offered for the software installed on their systems; if multiple updates apply, Microsoft says they can be installed in any order.

SharePoint Server 2016 uses the same KB number for Enterprise Server 2016​

Microsoft’s advisory includes a deployment clarification for older SharePoint naming. The updates for SharePoint Enterprise Server 2016 also apply to SharePoint Server 2016: the same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016.

Customers running either version should install the security update to be protected from this vulnerability. This matters for inventory and change-management teams whose asset records use one product name while their patch catalog, maintenance procedure, or administrator documentation uses the other.

The advisory’s instruction is not to select one package from a set arbitrarily. If the software installed on a server is offered multiple relevant updates, deploy all of them. Where an organization maintains separate SharePoint farms or roles, apply that check to each installed software set instead of assuming that an update approved for one server covers all components elsewhere.

What this means for you​

SharePoint administrators should treat CVE-2026-69409 as a confidentiality patch with a clear remediation target: deploy KB5002908 for Microsoft SharePoint Server Subscription Edition (x64) and verify fixed build 16.0.20326.20090.

  • Microsoft rates CVE-2026-69409 as Important, with a CVSS base score of 6.5 and temporal score of 5.7.
  • The vulnerability can expose legal-hold and eDiscovery metadata, including hold titles, descriptions, managers, and search criteria.
  • The described attacker is authorized and operates over the network, so review access in SharePoint environments that host sensitive legal and compliance material.
  • Install KB5002908 for Microsoft SharePoint Server Subscription Edition (x64) to reach fixed build 16.0.20326.20090.
  • Apply every update offered when multiple update packages apply to installed SharePoint software; Microsoft permits those applicable packages to be installed in any order.
  • SharePoint Server 2016 and SharePoint Enterprise Server 2016 use the same KB number for this security update.

CVE-2026-69409 is a focused SharePoint information-disclosure issue with an equally focused administrative response. Organizations that use SharePoint for legal hold, eDiscovery, or compliance workflows should make KB5002908 and build 16.0.20326.20090 part of the next controlled SharePoint servicing cycle, while ensuring all applicable update packages are included.