logo
search
Windows Integration Errors

Fix SharePoint 2019 Potentially Malicious XOML Node Error

Olivia MillerOlivia Miller Sep 29, 2026 869 views

Question details

Users encounter a 'potentially malicious XOML node' error when SharePoint 2010 Designer workflows attempt to run.

How to Fix the SharePoint 2019 Potentially Malicious XOML Node Error
Product
SharePoint 2019
Device & OS
not provided
Scenario
Executing SharePoint 2010 workflows involving CollectFeedbackTaskProcess after installing recent cumulative updates.
Observed behavior
The workflow fails to execute, and the system throws a security validation error about a potentially malicious XOML node, which is not resolved by just updating the web.config file.
Before you start

Ensure you have farm administrator privileges and take a backup of your web.config and owstimer.exe.config files before making modifications.

Solution 1Recommended

Allow-list Activities in Configuration Files

Explicitly allow-list the workflow activities in both the web application and timer service configuration files using the correct public key token.

Recent SharePoint updates introduced stricter validation for workflow XOML files. Adding the authorizedType entries to web.config alone is insufficient; the timer service must also be updated.

1
Locate configuration files

Find the web.config file for your specific SharePoint web application and the owstimer.exe.config file located in the SharePoint BIN directory.

2
Add authorizedType entries

Insert the required authorizedType elements for the CollectFeedbackTaskProcess activity into both configuration files.

3
Update the PublicKeyToken

Replace any 'null' values in the PublicKeyToken attribute with the actual public key token of the installed assembly.

4
Restart IIS and Timer Service

Apply the configuration changes consistently across all SharePoint servers in the farm, then run 'iisreset' from the command prompt and restart the SharePoint Timer Service via services.msc.

Allow-list Activities in Configuration Files
Configuration Consistency: It is recommended to use SharePoint web.config modifications through PowerShell to ensure changes are applied consistently across all servers in the farm.
Free Microsoft Office alternative

Need a Reliable Office Alternative?

While resolving complex SharePoint and Microsoft ecosystem errors, you might be seeking a simpler, lightweight productivity suite. WPS Office provides a free, highly compatible alternative to Microsoft Office for your daily document needs.

  1. 1. Download the installer: Visit the official WPS Office website and click the free download button for your operating system.
  2. 2. Install WPS Office: Run the setup file and follow the quick installation prompts to deploy the suite.
  3. 3. Open your files: Launch WPS Office and seamlessly open your existing Office documents without losing formatting.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats.Lightweight installation with low system resource requirements.Familiar user interface ensuring a seamless migration for your team.Cost-effective solution with robust enterprise-level productivity tools.
microsoft office alternative - wps office

Frequently Asked Questions

Why am I seeing a potentially malicious XOML node error after a SharePoint update?

Recent SharePoint 2019 Cumulative Updates introduced stricter security validation for workflow XOML files. If an activity like CollectFeedbackTaskProcess is not explicitly allow-listed with the correct public key token, SharePoint blocks it for security reasons.

Where is the owstimer.exe.config file located?

The owstimer.exe.config file is typically located in the SharePoint hive under the bin directory, commonly found at C:\Program Files\Common Files\microsoft shared\Web Server Extensions\16\BIN.

Are SharePoint 2010 workflows still supported in SharePoint 2019?

No, SharePoint 2010 workflows have been deprecated and are generally unsupported in modern environments. It is strongly recommended to migrate your workflows to Power Automate or another supported platform.