CRITICAL

CVE-2026-56164

Microsoft Sharepoint Server 2026-07-14 CVSS v3.1
CVSS
9.8
KEV

Description

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Summary dbcve.org

This is a critical authentication bypass vulnerability in Microsoft Office SharePoint where a critical function lacks proper authentication controls. An unauthenticated remote attacker can exploit this to elevate their privileges to administrative levels within the SharePoint environment.

Mitigation

Apply Microsoft security updates for SharePoint immediately; review SharePoint access logs for indicators of compromise; verify that all SharePoint service accounts follow least-privilege principles.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

26.64%
Probability of exploitation in next 30 days
97.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE