Missing Authentication for Critical Function in Microsoft SharePoint Server - CVE-2026-56164
Published: July 14, 2026 / Updated: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to missing authentication for critical function. A remote non-authenticated attacker can send a specially crafted HTTP request and modify certain data.
Note, the vulnerability is being actively exploited in the wild.