SharePoint JWT Bypass Exposes On-Premises Sites
CVE-2026-55040 allows unauthenticated attackers to masquerade as SharePoint users. Rapid7 reports CVSS 9.1. The auth bypass breaks the chain before the planned RCE component is rolled out in August.
Key Takeaways
- Patch authentication first. CVE-2026-55040 is the entry point. Without a valid session, the RCE chain described by Rapid7 breaks.
- Identity is sufficient. The target user’s SID or UPN is enough as a prerequisite for impersonation.
- Prioritize on-premises. Internet-exposed SharePoint servers are the urgent inventory, not just the CVE list.
- Second zero‑day under scrutiny. CVE-2026-56164 (SharePoint EoP) has already been exploited according to Microsoft. Check AMSI mitigations.
Related:The weakest supplier opens the critical installation / A signed driver makes endpoint protection blind
What CVE-2026-55040 Breaks
What is the SharePoint JWT Bypass? CVE-2026-55040 is a vulnerability in Microsoft SharePoint’s JWT token validation. An unauthenticated remote attacker can bypass authentication and act as a site user or administrator, provided they know the target identity.
Stephen Fewer of Rapid7 Labs discovered the flaw as part of a zero‑day research project. Coordination with Microsoft began on May 18, 2026. On July 14, 2026, public disclosure was released along with the July patch.
CVSS v3.1 for CVE-2026-55040 (Critical)
Source: Rapid7 / FIRST-Rechner
The prerequisite is precise: the attacker must know the target-such as an Active Directory SID or UPN (typically resembling an email address). Afterwards, they can assume the identity. Rapid7 details SID enumeration plus identity takeover up to site administrator in the proof‑of‑concept illustration.
Definition · JWT-Auth-Bypass
An attacker bypasses token verification and impersonates a known SharePoint user without knowing their password.
Why the Auth Bypass Stops the RCE Chain
Rapid7 linked the bypass to a separate RCE vulnerability that enables unauthorized remote code execution. Microsoft had scheduled the RCE component for the August patch cycle. The July fix for CVE-2026-55040 already breaks this chain. Auth bypasses are therefore not minor issues-they fully expose the authenticated attack surface.
At the same time, the July patch Tuesday addresses CVE-2026-56164, a SharePoint elevation-of-privilege vulnerability that Microsoft reports is actively exploited (CVSS 5.3, Moderate). Affected: SharePoint Server 2016, 2019, and Subscription Edition. Microsoft points to AMSI integration as an additional detection mechanism for malicious POST requests. This does not replace the patch but complements it.
Priority for DACH Admins
First, inventory: Which SharePoint servers are on‑prem and reachable from the internet? Every such instance is a hotfix. Next, check the patch level against the July updates. Document the builds. Have a rollback plan ready, but don’t delay patching.
Next, identity traces: unusual site‑admin activity, new web parts, suspicious file uploads, token and auth anomalies in the logs. Those who only tick CVEs and ignore exposure waste time.
On-Prem-SharePoint now
- ✓Apply July-2026 Updates for SharePoint Server and verify the build standard
- ✓Inventory internet‑exposed SharePoint instances and kill exposure
- ✓Check AMSI integration for SharePoint (Microsoft mitigation for related EoP paths)
- ✓Audit admin and site accounts for unusual logins and token patterns
- ✓Track separate auth bypass and RCE chain: plan August patch for RCE component
What the Board Must Include
On-Prem SharePoint stays an attack surface while authentication paths remain weak and instances are exposed. CVE-2026-55040 demonstrates that collaboration platforms occupy the management layer. Patching them and disconnecting them from the Internet breaks the chain. Those who delay end up purchasing the August-RCE component at a higher cost.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
Is CVE-2026-55040 remotely exploitable?
Yes. Rapid7 describes a remote, unauthenticated attack path. The prerequisite is knowledge of the target identity (SID or UPN).
Does the July patch hold up against the full RCE chain?
He breaks the chain described by Rapid7 at the Auth-Bypass. The separate RCE component is slated to follow in the August cycle. Nevertheless, patch immediately.
Is it about SharePoint Online?
The disclosure targets SharePoint Server and the JWT validation pipeline of the affected server products. The Microsoft Security Response Center (MSRC) entry for the respective build provides the exact patch scope.
What is the difference to CVE-2026-56164?
56164 is an EoP (Exploit) with confirmed exploitation in the wild. 55040 is the JSON Web Token authentication bypass with CVSS 9.1 and chain potential to RCE.
Which mitigation counts besides the patch?
Reduce internet exposure, enable AMSI for SharePoint, monitor admin accounts, and alert on unusual site operations.
Lesetipps der Redaktion
LesetippDer schwächste Zulieferer öffnet die kritische AnlageLesetippEin signierter Treiber macht den Endpunktschutz blindLesetippWas ist KRITIS? Betreiber, Pflichten und Schwellen
Mehr aus dem MBF Media Netzwerk
cloudmagazinWenn GPUs den SaaS-Etat auffressenMyBusinessFutureWann sich ein deutsches KI-Modell wirklich rechnetDigital ChiefsDie Rechnung für zehn Jahre Insellösungen





