Rapid7, Microsoft Disclose SharePoint CVE-2026-55040, a 9.1 Authentication Bypass
Updated
Updated · rapid7.com · Jul 17
Rapid7, Microsoft Disclose SharePoint CVE-2026-55040, a 9.1 Authentication Bypass
3 articles · Updated · rapid7.com · Jul 17
Summary
CVE-2026-55040 lets an unauthenticated attacker impersonate any known SharePoint user or administrator on a vulnerable server, giving access to perform actions under that account.
JWT token validation flaws drive the bug, and Rapid7 said it can identify targets through Active Directory SID enumeration or a user's UPN before bypassing login.
Rapid7 chained the flaw with a second SharePoint bug to achieve unauthenticated remote code execution, but said patching CVE-2026-55040 breaks that exploit chain; the RCE fix is due in Microsoft's August 2026 update cycle.
Microsoft acknowledged Rapid7's coordinated disclosure, advised customers to apply the latest updates, and Rapid7 said technical details will be published within 30 days.