Web Hack List

Preliminary research

SharePoint CVE-2026-65660: From Anonymous Access to Pre-Auth RCE via EditingPageParser Type-Check Bypass

AI-collected research leads through 29 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

SharePoint validated directive fragments separately before reconstructing markup. Splitting a registration directive across those fragments bypassed SafeControls checks and reached XAML execution gadgets. An alternate page hosted the vulnerable component; the anonymous chain required anonymous content access and a separate unpatched authentication path.

Record

Researcher
khoadha
Published by
Viettel Cyber Security
Date
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of khoadha, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .