Exploitation Summary
EIP tracks 1 public exploit for CVE-2026-26114. PoCs published by huynambka.
AI-analyzed exploit summary This repository contains a full-chain exploit for CVE-2026-26114, a SharePoint vulnerability combining a Taxonomy SQL injection primitive with AppLifecycle NDCS deserialization to achieve unauthenticated remote code execution. The exploit leverages blind SQLi in CustomSortOrder to inject rogue AppJobs/AppTasks, then triggers OWSTIMER.EXE to deserialize attacker-controlled TaskData using NetDataContractSerializer.
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Exploits (1)
This repository contains a full-chain exploit for CVE-2026-26114, a SharePoint vulnerability combining a Taxonomy SQL injection primitive with AppLifecycle NDCS deserialization to achieve unauthenticated remote code execution. The exploit leverages blind SQLi in CustomSortOrder to inject rogue AppJobs/AppTasks, then triggers OWSTIMER.EXE to deserialize attacker-controlled TaskData using NetDataContractSerializer.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H