Black & White Path
Aug 10, 2026 · Information Security
CVE-2026-45454: SharePoint Server Upload.aspx Path Traversal Leads to Remote Code Execution
The AretiQ security team disclosed a path‑traversal flaw in SharePoint Server's Upload.aspx page that lets an authenticated user with Contribute rights upload files to any library, and when PageParserPaths permits server‑side scripts, an ASPX webshell can be executed for full remote code execution, with CVSS 3.1 score 6.5 (Microsoft 8.2).
CVE-2026-45454Path TraversalPowerShell
0 likes · 14 min read
