Weak Authentication in Microsoft SharePoint Server - CVE-2026-55040

 

Weak Authentication in Microsoft SharePoint Server - CVE-2026-55040

Published: July 17, 2026 / Updated: August 14, 2026


Vulnerability identifier: #VU138275
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55040
CWE-ID: CWE-1390
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to bypass an authentication security feature.

The vulnerability exists due to weak authentication in Microsoft Office SharePoint when handling network requests. A remote attacker can make an anonymous connection to bypass an authentication security feature.

Successful exploitation can allow impersonation, disclosure of files, and modification of data.


Affected software

Microsoft SharePoint Server

How to mitigate CVE-2026-55040

Install security update from vendor's website.

Microsoft SharePoint Server - addressed in versions 16.0.5561.1001, 16.0.10417.20175, 16.0.19725.20434

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins