securityonline.info 8/12/2026, 9:52:10 AM · external

Critical SharePoint JWT flaw lets attackers bypass authentication

Critical SharePoint JWT flaw lets attackers bypass authentication
CyberSIXT Evidence Panel
Primary Source rapid7.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

THE page discusses a critical security vulnerability (CVE-2026-55040) affecting Microsoft SharePoint, enabling unauthorized users to bypass authentication by forging JSON Web Tokens (JWT). The issue has a CVSS score of 9.1, indicating its severity. Rapid7 released a proof-of-concept exploit, and the vulnerability affects versions of SharePoint including Server 2016 and 2019. Although no confirmed exploitation has been reported, the public disclosure increases risk. Users are urged to apply patches from July 2026 to mitigate the risk and monitor for suspicious activities.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline