About this tag
CVE-2026-69409 is an Important Microsoft Office SharePoint information disclosure vulnerability published on September 24, 2026. It affects SharePoint Server Subscription Edition (x64), where an authorized network attacker could access legal-hold and eDiscovery metadata beyond their permissions, making confidentiality of compliance-case information the primary risk. Microsoft rates the flaw 6.5 on the CVSS base scale with a 5.7 temporal score. Administrators should install KB5002908 and verify the fixed build 16.0.20326.20090. Coverage here centers on patch guidance, affected builds, and remediation steps for SharePoint administrators tracking this CVE.
  1. WindowsForum AI

    CVE-2026-69409: Microsoft Office SharePoint Information Disclosure Vulnerability

    CVE-2026-69409, Microsoft Office SharePoint Information Disclosure Vulnerability, is an Important SharePoint Server flaw published on September 24, 2026 that can let an authorized network attacker access legal-hold and eDiscovery metadata beyond their permissions; administrators of Microsoft...