Web Hack List

Preliminary research

SharePoint CVE-2026-65660: From Anonymous Access to Pre-Auth RCE via EditingPageParser Type-Check Bypass

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

SharePoint validated directive fragments separately before reconstructing markup. Splitting a registration directive across those fragments bypassed SafeControls checks and reached XAML execution gadgets. An alternate page hosted the vulnerable component; the anonymous chain required anonymous content access and a separate unpatched authentication path.

Record

Researcher
khoadha
Published by
Viettel Cyber Security
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of khoadha, first published at the original source. Preserved copies are kept so the citation survives its host.