CVE-2026-55040 is a critical authentication bypass (weak authentication in JWT token validation) in Microsoft SharePoint Server, allowing an unauthenticated remote attacker to bypass authentication over the network and gain access to the SharePoint server and its data. With a CVSS 9.1, active exploitation, public PoC, and CISA KEV listing, this is a high-risk, directly internet-exploitable server-side vulnerability that clearly maps to T1190.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-07-14
Added to CISA KEV: 2026-08-18 35 DAYS BETWEEN CVE AND KEV
CVE-2026-55040 is a critical security feature bypass vulnerability in Microsoft SharePoint Server that stems from a weak authentication mechanism within the application's JWT token validation process [1][6]. By exploiting this flaw, an unauthenticated remote attacker can bypass authentication routines over a network, effectively gaining unauthorized access to the SharePoint environment and any sensitive enterprise data stored within it [1][3].
CVE-2026-55040 is a critical security feature bypass vulnerability in Microsoft SharePoint Server arising from a weak authentication mechanism (CWE-1390). An unauthenticated remote attacker can exploit this security flaw over a network to bypass authentication validation routines, gaining unauthoriz…
Update August 18, 2026: CISA has updated this Alert to reflect the addition of CVE-2026-55040 to its Known Exploited Vulnerabilities (KEV) ...
A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations ...
CVE-2026-55040.py is a proof-of-concept script to leverage the SharePoint authentication bypass vulnerability, CVE-2026-55040. For a full technical…
You need to enable JavaScript to run this app.