Preliminary research
SharePoint CVE-2026-65660: From Anonymous Access to Pre-Auth RCE via EditingPageParser Type-Check Bypass
AI-collected research leads through 29 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
SharePoint validated directive fragments separately before reconstructing markup. Splitting a registration directive across those fragments bypassed SafeControls checks and reached XAML execution gadgets. An alternate page hosted the vulnerable component; the anonymous chain required anonymous content access and a separate unpatched authentication path.
Record
- Researcher
- khoadha
- Published by
- Viettel Cyber Security
- Date
- Topic
- Server
In the archive
Related sources
- Exploiting ASP.NET TemplateParser — Part I: Sitecore (CVE-2023-35813)
- Exploiting ASP.NET TemplateParser — Part II: SharePoint (CVE-2023-33160)
- SharePoint ToolShell – One Request PreAuth RCE chain CVE-2025-53770
- Transformers: Dark Side of the Type — Weaponizing the Conversion Layer Whitepaper
- Earlier directive-injection analysis (May 2026, Vietnamese)
Tags
This page is the archive's own catalogue record. The research is the work of khoadha, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .