CVE-2026-55040 PoC: Microsoft SharePoint JWT authentication bypass
github.com | tool | CVE-2026-55040 | #public-poc | #authentication-bypass | #microsoft | #pre-auth | #sharepoint | #jwt | #exploit | #poc | #cve-2026-55040
Summary
A PoC for CVE-2026-55040: exploit code that constructs an authentication header for any valid account, demonstrating a JWT authentication bypass in Microsoft SharePoint.
Why it matters
The public PoC can generate a forged authentication token for a specified account, substantially lowering the barrier to validation and reproduction. Apply Microsoft security updates immediately and test only in isolated, authorized environments.
- Vendor
- Microsoft
- Product
- SharePoint Server
- Affected versions
- SharePoint 2016 < 16.0.5561.1001; 2019 < 16.0.10417.20175; Subscription Edition < 16.0.19725.20434
- CVSS
- 9.1
- Published
- Collected
Skip to content