S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Nov 21, 2025

CVE-2025-49706 Scanner

CVE-2025-49706 Scanner - Improper Authentication vulnerability in Microsoft SharePoint Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-49706
6.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.
Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Microsoft SharePoint Enterprise Server 2016by Microsoft
AFFECTED< 16.0.5508.1000SAFE ✓≥ 16.0.5508.1000
Microsoft SharePoint Server 2019by Microsoft
AFFECTED< 16.0.10417.20027SAFE ✓≥ 16.0.10417.20027
Microsoft SharePoint Server Subscription Editionby Microsoft
AFFECTED< 16.0.18526.20424SAFE ✓≥ 16.0.18526.20424
Updated Sep 9, 2026View on NVD →
Detail

Microsoft SharePoint Server is an enterprise solution used for managing and storing documents. It is widely adopted by organizations to create websites and collaborative workspaces. IT administrators and content managers utilize SharePoint for its content management and document storage capabilities. As a web-based platform, it is commonly utilized in various environments including corporate intranets and web applications. Administrators leverage it for its integration with other Microsoft products and ease of use for team collaboration. Its role in improving productivity through streamlined information sharing is paramount.

The vulnerability involves improper authentication within Microsoft Office SharePoint. It can allow an unauthorized attacker to perform spoofing over a network. By lacking strict authentication checks, the system can be misled into accepting illegitimate credentials. This vulnerability could be exploited by attackers to impersonate other users or gain unauthorized access. The improper handling of authentication procedures prompts significant security risks. Such gaps in security could potentially expose sensitive organizational data to unauthorized parties.

Technically, the vulnerability can be targeted through weak endpoints within SharePoint's authentication framework. The issue lies in HTTP requests made to specific URLs without proper verification of user credentials. Attackers can manipulate parameters such as 'MSOTlPn_Uri' and 'MSOTlPn_DWP' in HTTP Post requests. The vulnerability is indicated by receiving specific response status codes from the server. For instance, codes like 301 and 302 signal an object moved, hinting at the bypass. The lack of stringent control measures is a clear technical flaw in the software's design.

Exploitation of the vulnerability may lead to unauthorized data access or resource manipulation. Attackers can spoof identities to retrieve confidential documents or perform unauthorized actions. This may result in exposure of sensitive enterprise information, potentially used for malicious purposes. Companies might face compliance breaches and loss of trust due to data compromise. Additionally, the organization could incur financial losses due to unauthorized transactions or reputational damage. Prompt identification and patching are critical to prevent such threats.

REFERENCES

Solution Advice
  • Implement multi-factor authentication to enhance security.
  • Regularly update SharePoint Server to the latest version to include security patches.
  • Conduct periodic security audits to identify and rectify authentication flaws.
  • Restrict network access to the SharePoint Server to authorize users only.
  • Monitor access logs for suspicious activities and investigate unauthorized access attempts promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-49706 Scanner - Improper Authentication vulnerability in Microsoft SharePoint Server | S4E