Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-55040 PoC: Microsoft SharePoint JWT authentication bypass

Summary

A PoC for CVE-2026-55040: exploit code that constructs an authentication header for any valid account, demonstrating a JWT authentication bypass in Microsoft SharePoint.

Why it matters

The public PoC can generate a forged authentication token for a specified account, substantially lowering the barrier to validation and reproduction. Apply Microsoft security updates immediately and test only in isolated, authorized environments.
Vendor
Microsoft
Product
SharePoint Server
Affected versions
SharePoint 2016 < 16.0.5561.1001; 2019 < 16.0.10417.20175; Subscription Edition < 16.0.19725.20434
CVSS
9.1
Published
Collected

original ↗

Related coverage

back