Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
Tue, 11 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in hypershift-addon-operator. A hub-cluster administrator with write access to the hypershift-operator-install-flags ConfigMap can inject malicious command-line arguments into the privileged install Job. This vulnerability, known as argument injection, allows the attacker to pull arbitrary container images and gain full administrative control (cluster-admin code execution) on managed spoke clusters. | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| Title | hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection) | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| First Time appeared |
Microsoft
Microsoft sharepoint Server Microsoft sharepoint Server 2016 Microsoft sharepoint Server 2019 |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft sharepoint Server Microsoft sharepoint Server 2016 Microsoft sharepoint Server 2019 |
|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 07 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hypershift
Hypershift addon Operator |
|
| Vendors & Products |
Hypershift
Hypershift addon Operator |
Fri, 07 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in hypershift-addon-operator. A hub-cluster administrator with write access to the hypershift-operator-install-flags ConfigMap can inject malicious command-line arguments into the privileged install Job. This vulnerability, known as argument injection, allows the attacker to pull arbitrary container images and gain full administrative control (cluster-admin code execution) on managed spoke clusters. | |
| Title | hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection) | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-08-14T18:09:35.272Z
Reserved: 2026-07-27T19:02:26.601Z
Link: CVE-2026-66808
Updated: 2026-08-11T18:26:57.237Z
Status : Analyzed
Published: 2026-08-11T17:19:02.233
Modified: 2026-08-13T13:41:49.857
Link: CVE-2026-66808
OpenCVE Enrichment
Updated: 2026-08-13T01:45:02Z