THREAT BRIEFING · 10.09.2026 DEENFRES

Practice & Implementation

SharePoint JWT Bypass Exposes On-Premises Sites

By Alec Chizhik · July 15, 2026 · 5 min read

CVE-2026-55040 allows unauthenticated attackers to masquerade as SharePoint users. Rapid7 reports CVSS 9.1. The auth bypass breaks the chain before the planned RCE component is rolled out in August.

Key Takeaways

  • Patch authentication first. CVE-2026-55040 is the entry point. Without a valid session, the RCE chain described by Rapid7 breaks.
  • Identity is sufficient. The target user’s SID or UPN is enough as a prerequisite for impersonation.
  • Prioritize on-premises. Internet-exposed SharePoint servers are the urgent inventory, not just the CVE list.
  • Second zero‑day under scrutiny. CVE-2026-56164 (SharePoint EoP) has already been exploited according to Microsoft. Check AMSI mitigations.

Related:The weakest supplier opens the critical installation  /  A signed driver makes endpoint protection blind

What CVE-2026-55040 Breaks

What is the SharePoint JWT Bypass? CVE-2026-55040 is a vulnerability in Microsoft SharePoint’s JWT token validation. An unauthenticated remote attacker can bypass authentication and act as a site user or administrator, provided they know the target identity.

Stephen Fewer of Rapid7 Labs discovered the flaw as part of a zero‑day research project. Coordination with Microsoft began on May 18, 2026. On July 14, 2026, public disclosure was released along with the July patch.

9,1

CVSS v3.1 for CVE-2026-55040 (Critical)

Source: Rapid7 / FIRST-Rechner

The prerequisite is precise: the attacker must know the target-such as an Active Directory SID or UPN (typically resembling an email address). Afterwards, they can assume the identity. Rapid7 details SID enumeration plus identity takeover up to site administrator in the proof‑of‑concept illustration.

Definition · JWT-Auth-Bypass

An attacker bypasses token verification and impersonates a known SharePoint user without knowing their password.

Why the Auth Bypass Stops the RCE Chain

Rapid7 linked the bypass to a separate RCE vulnerability that enables unauthorized remote code execution. Microsoft had scheduled the RCE component for the August patch cycle. The July fix for CVE-2026-55040 already breaks this chain. Auth bypasses are therefore not minor issues-they fully expose the authenticated attack surface.

At the same time, the July patch Tuesday addresses CVE-2026-56164, a SharePoint elevation-of-privilege vulnerability that Microsoft reports is actively exploited (CVSS 5.3, Moderate). Affected: SharePoint Server 2016, 2019, and Subscription Edition. Microsoft points to AMSI integration as an additional detection mechanism for malicious POST requests. This does not replace the patch but complements it.

Priority for DACH Admins

First, inventory: Which SharePoint servers are on‑prem and reachable from the internet? Every such instance is a hotfix. Next, check the patch level against the July updates. Document the builds. Have a rollback plan ready, but don’t delay patching.

Next, identity traces: unusual site‑admin activity, new web parts, suspicious file uploads, token and auth anomalies in the logs. Those who only tick CVEs and ignore exposure waste time.

On-Prem-SharePoint now

  • Apply July-2026 Updates for SharePoint Server and verify the build standard
  • Inventory internet‑exposed SharePoint instances and kill exposure
  • Check AMSI integration for SharePoint (Microsoft mitigation for related EoP paths)
  • Audit admin and site accounts for unusual logins and token patterns
  • Track separate auth bypass and RCE chain: plan August patch for RCE component

What the Board Must Include

On-Prem SharePoint stays an attack surface while authentication paths remain weak and instances are exposed. CVE-2026-55040 demonstrates that collaboration platforms occupy the management layer. Patching them and disconnecting them from the Internet breaks the chain. Those who delay end up purchasing the August-RCE component at a higher cost.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Is CVE-2026-55040 remotely exploitable?

Yes. Rapid7 describes a remote, unauthenticated attack path. The prerequisite is knowledge of the target identity (SID or UPN).

Does the July patch hold up against the full RCE chain?

He breaks the chain described by Rapid7 at the Auth-Bypass. The separate RCE component is slated to follow in the August cycle. Nevertheless, patch immediately.

Is it about SharePoint Online?

The disclosure targets SharePoint Server and the JWT validation pipeline of the affected server products. The Microsoft Security Response Center (MSRC) entry for the respective build provides the exact patch scope.

What is the difference to CVE-2026-56164?

56164 is an EoP (Exploit) with confirmed exploitation in the wild. 55040 is the JSON Web Token authentication bypass with CVSS 9.1 and chain potential to RCE.

Which mitigation counts besides the patch?

Reduce internet exposure, enable AMSI for SharePoint, monitor admin accounts, and alert on unusual site operations.

Lesetipps der Redaktion

LesetippDer schwächste Zulieferer öffnet die kritische AnlageLesetippEin signierter Treiber macht den Endpunktschutz blindLesetippWas ist KRITIS? Betreiber, Pflichten und Schwellen

Mehr aus dem MBF Media Netzwerk

cloudmagazinWenn GPUs den SaaS-Etat auffressenMyBusinessFutureWann sich ein deutsches KI-Modell wirklich rechnetDigital ChiefsDie Rechnung für zehn Jahre Insellösungen

Further reading

Practice & Implementation · July 31, 2026

Anthropic: Claude Breached Three Companies

Anthropic's Claude compromised three organizations in cyber evaluations. Harness misconfiguration, PyPI malware, and CISO checklist insights.

Practice & Implementation · July 29, 2026

Codex Security: Open Client Feeds OpenAI

Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.

A magazine by Evernine Media GmbH