Microsoft and Rapid7 disclosed CVE-2026-55040, an authentication bypass flaw in Microsoft SharePoint that allows a remote, unauthenticated attacker to impersonate a SharePoint site user or administrator. Rapid7 said the issue originates in SharePoint’s JWT token validation pipeline, aligning with the broader CWE-1390 Weak Authentication class in which identity checks fail to adequately verify a claimed user and can lead to unauthorized access and privilege abuse.
Microsoft has issued SharePoint updates addressing CVE-2026-55040, while Rapid7 reported the bug can be chained with a separate SharePoint remote code execution vulnerability to achieve unauthenticated RCE. Microsoft scored the authentication bypass at CVSS 5.3 and said the RCE component is planned for a later update cycle; Rapid7 noted that fixing the JWT flaw breaks the exploit chain that was developed during zero-day research for Pwn2Own Berlin.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft released a SharePoint update that fixed CVE-2026-55040, according to Rapid7's disclosure and Microsoft's SharePoint updates page. Rapid7 noted Microsoft planned to address the separate RCE component in the August 2026 update cycle.
Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability in Microsoft SharePoint that can allow a remote unauthenticated attacker to impersonate a SharePoint site user or administrator. Rapid7 said the flaw stems from multiple issues in the JWT token validation pipeline and that fixing it breaks an unauthenticated RCE exploit chain.
Rapid7 reported that the successful exploit chain emerged during its March 2026 research sprint. The chain combined the JWT authentication bypass with a separate SharePoint remote code execution issue.
Rapid7 said it used agentic AI-assisted research on SharePoint during a January 2026 research sprint as part of the work that eventually led to the exploit chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
rapid7.com
Open sourcelearn.microsoft.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.