CRITICAL
CVE-2026-55040
CVSS
9.1
KEV
Description
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Summary dbcve.org
This is a critical authentication bypass vulnerability in Microsoft Office SharePoint that allows unauthenticated attackers to circumvent security controls over a network. The weakness in authentication mechanisms enables unauthorized access to SharePoint resources without proper credentials.
Mitigation
Apply Microsoft security updates immediately upon release. Review SharePoint authentication configurations and audit access logs for indicators of compromise. Consider implementing additional network-level access controls as a temporary measure until the patch is available.
Weakness (CWE)
CWE-1390
EPSS Score
50.59%
Probability of exploitation in next 30 days
98.9th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040
Patch, Vendor Advisory
https://github.com/sfewer-r7/CVE-2026-55040
Exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55040
Exploit, Third Party Advisory
https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.