CVE-2026-33112: SharePoint XmlValidator Bypass Enables Low-Privilege RCE
blog.viettelcybersecurity.com | vulnerability | CVE-2026-33112 | #rce | #deserialization | #sharepoint | #xml | #cve-2026-33112 | #performancepoint
Summary
CVE-2026-33112: a network-imported XSD schema bypasses SharePoint's XmlValidator, and the PerformancePoint PPSAuthoringService revives ExcelDataSet deserialization for low-privilege RCE.
- Published
- Collected
Skip to content