CVE-2026-55040 Details
Description
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
A vulnerability exists in Microsoft Office SharePoint that allows unauthorized attackers to bypass authentication over the network, effectively circumventing a security feature. This weakness arises from inadequate authentication mechanisms, enabling attackers to impersonate users.
Users can download the security update for Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 from the Microsoft Update Catalog. Specific KB articles for each version are also available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/sfewer-r7/CVE-2026-55040 | CISA-ADP | Exploit |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55040 | CISA-ADP | ExploitThird Party Advisory |
| https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/ | CISA-ADP | US Government Resource |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040 | [email protected] | PatchVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Microsoft SharePoint Weak Authentication Vulnerability | Aug 18, 2026 | Aug 21, 2026 | Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1390 | Weak Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft sharepoint server | < 16.0.19725.20434 2016 2019 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 19, 2026 | CVE Modified | CISA-ADP |
| Aug 18, 2026 | Modified Analysis | [email protected] |
| Aug 18, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Aug 18, 2026 | CVE Modified | CISA-ADP |
| Aug 13, 2026 | CVE Modified | CISA-ADP |
| Aug 13, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |