CVE-2026-47294
HIGHMicrosoft Office SharePoint - Remote Code Execution via Untrusted Data Deserialization
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-47294. PoCs published by wnaspy.
AI-analyzed exploit summary The repository contains a ZIP file with obfuscated Python scripts, but no clear exploit code or technical details are provided. The filenames suggest a SharePoint exploit, but the content is heavily obfuscated and lacks legitimate documentation.
Description
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Exploits (1)
The repository contains a ZIP file with obfuscated Python scripts, but no clear exploit code or technical details are provided. The filenames suggest a SharePoint exploit, but the content is heavily obfuscated and lacks legitimate documentation.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H