CRITICAL
CVE-2026-56164
CVSS
9.8
KEV
Description
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Summary dbcve.org
This is a critical authentication bypass vulnerability in Microsoft Office SharePoint where a critical function lacks proper authentication controls. An unauthenticated remote attacker can exploit this to elevate their privileges to administrative levels within the SharePoint environment.
Mitigation
Apply Microsoft security updates for SharePoint immediately; review SharePoint access logs for indicators of compromise; verify that all SharePoint service accounts follow least-privilege principles.
Weakness (CWE)
CWE-306
Missing Authentication
EPSS Score
26.64%
Probability of exploitation in next 30 days
97.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.