{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-32201",
  "revision": 1,
  "title": "Microsoft SharePoint Server — input validation enables spoofing",
  "summary": "Microsoft SharePoint Server does not validate input properly, so an unauthenticated attacker on the network can make content appear to come from somewhere it did not. The vendor entry does not say which input, or what gets spoofed.",
  "source_type": "cve",
  "severity": "medium",
  "cvss": {
    "score": 6.5,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
    "version": "3.1"
  },
  "epss": 0.43378,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-04-14",
    "prerequisites": "Network access to the SharePoint server; no credentials needed."
  },
  "kill_chain": "defense_evasion",
  "recommended_action": "Install the Microsoft update for this CVE now; until it is on, treat the stated origin of SharePoint-hosted content as something to confirm out of band.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-32201",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-32201",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-32201",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32201",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201"
    },
    {
      "type": "writeup",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-32201"
    }
  ],
  "published_at": "2026-04-14T18:17:27.160Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "microsoft",
    "sharepoint",
    "spoofing",
    "kev"
  ]
}
