CVE-2026-62837

Office: Relative Path Traversal (CVE-2026-62837)

mediumEPSS 1.2%

Affected

  • Microsoft/Access 2016..*
  • Microsoft/Azure SQL Managed Instance..*
  • Microsoft/Excel 2016..*
  • Microsoft/Office 2016..*
  • Microsoft/Office LTSC for Mac 2021..*
  • Microsoft/Office LTSC 2021..*
  • Microsoft/Office LTSC for Mac 2024..*
  • Microsoft/Office LTSC 2024..*
  • Microsoft/Office 2019..*
  • Microsoft/Office 365 for Mac..*
  • Microsoft/OneDrive for MacOS..*
  • Microsoft/Outlook 2016..*
  • Microsoft/PowerPoint 2016..*
  • Microsoft/Service Bus Azure Service Bus..*
  • Microsoft/SharePoint Enterprise Server 2016..*
  • Microsoft/SharePoint Server Subscription Edition..*
  • Microsoft/SharePoint Online..*
  • Microsoft/Teams for iOS..*
  • Microsoft/Teams for Android..*
  • Microsoft/Word 2016..*

Description

Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

MicrosoftAccess
2016
MicrosoftAzure
SQL Managed Instance
MicrosoftExcel
2016
MicrosoftOffice
20162019LTSC 2021LTSC 2024LTSC for Mac 2021LTSC for Mac 2024
MicrosoftOffice 365
for Mac
MicrosoftOneDrive
for MacOS
MicrosoftOutlook
2016
MicrosoftPowerPoint
2016
MicrosoftService Bus
Azure Service Bus
MicrosoftSharePoint
Enterprise Server 2016OnlineServer Subscription Edition
MicrosoftTeams
for Androidfor iOS
MicrosoftWord
2016

Metrics

6.5
Source: nvd-v3
68.1 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
medium
no public PoC known
1.2 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-08-11 17:03 UTC
CWE-23

Weakness classes (CWE)

  • CWE-23Base

    Relative Path Traversal

    The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-11 21:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-62837","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. Initial Analysis2026-08-11 20:51 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* versions up to (excluding) 16.0.19725.20522
    • Reference Type: Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62837 Types: Patch, Vendor Advisory
  3. New CVE Received2026-08-11 17:18 UTC· secure@microsoft.com
    • Affected: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
    • Description: Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
    • CWE: CWE-23

Linked advisories