🔴 CVE-2026-55040

CVE-2026-55040 is a critical authentication bypass (weak authentication in JWT token validation) in Microsoft SharePoint Server, allowing an unauthenticated remote attacker to bypass authentication over the network and gain access to the SharePoint server and its data. With a CVSS 9.1, active exploitation, public PoC, and CISA KEV listing, this is a high-risk, directly internet-exploitable server-side vulnerability that clearly maps to T1190.

← Back to Overview
HIGH_RISK
Risk Level
9.1
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-07-14

Added to CISA KEV: 2026-08-18 35 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-09-14)

Summary

CVE-2026-55040 is a critical security feature bypass vulnerability in Microsoft SharePoint Server that stems from a weak authentication mechanism within the application's JWT token validation process [1][6]. By exploiting this flaw, an unauthenticated remote attacker can bypass authentication routines over a network, effectively gaining unauthorized access to the SharePoint environment and any sensitive enterprise data stored within it [1][3].

Exploitation

  • Active Exploitation: The vulnerability is currently being exploited in the wild, leading to its inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog as of August 18, 2026 [2].
  • Threat Actors/Campaigns: While specific attribution to threat actors is evolving, the active exploitation and the availability of proof-of-concept code indicate a high risk of widespread misuse by various adversaries [2].
  • Availability of Proof-of-Concept: Publicly available proof-of-concept (PoC) exploit scripts, such as `CVE-2026-55040.py`, exist to demonstrate and facilitate the authentication bypass [4].
  • Attack Prerequisites: The attack can be performed remotely over a network by an unauthenticated attacker; it requires no local access, no prior authentication, and no user interaction [1][3].

Affected Products & Patches

  • Affected Products: Microsoft SharePoint Server and related components relying on the vulnerable JWT authentication module are affected [6][7].
  • Patch Availability: Organizations should refer to the official Microsoft Security Update Guide for specific patches and cumulative updates addressing this CVE [5].
  • Mitigations: In addition to applying patches, CISA recommends general SharePoint hardening measures to minimize the attack surface for internet-facing deployments [2].

Impact

  • Capability: Successful exploitation grants an unauthorized user the ability to bypass authentication validation, effectively acting as an authenticated user within the target SharePoint instance [3].
  • Business Risk: For internet-facing deployments, this vulnerability poses a severe risk, as it allows external, unauthenticated attackers to gain complete control over sensitive enterprise data, potentially leading to unauthorized data exfiltration, modification, or further lateral movement within the corporate network [1].

Sources

  1. CVE-2026-55040: CVE-2026-55040: Microsoft SharePoint Server Security ...

    CVE-2026-55040 is a critical security feature bypass vulnerability in Microsoft SharePoint Server arising from a weak authentication mechanism (CWE-1390). An unauthenticated remote attacker can exploit this security flaw over a network to bypass authentication validation routines, gaining unauthoriz…

  2. CISA Urges SharePoint Hardening After New Exploitations

    Update August 18, 2026: CISA has updated this Alert to reflect the addition of CVE-2026-55040 to its Known Exploited Vulnerabilities (KEV) ...

  3. Microsoft SharePoint JWT Token Authentication Bypass ...

    A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations ...

  4. GitHub - sfewer-r7/CVE-2026-55040: Microsoft SharePoint ...

    CVE-2026-55040.py is a proof-of-concept script to leverage the SharePoint authentication bypass vulnerability, CVE-2026-55040. For a full technical…

  5. Microsoft Security Update Guide CVE-2026-55040

    You need to enable JavaScript to run this app.