Authentication Bypass in Microsoft Office SharePoint by Microsoft
CVE-2026-56164

5.3MEDIUM

Key Information:

Badges

📈 Score: 822💰 Ransomware👾 Exploit Exists🟡 Public PoC🟣 EPSS 22%🦅 CISA Reported📰 News Worthy

What is CVE-2026-56164?

CVE-2026-56164 is a significant vulnerability identified within Microsoft Office SharePoint, a widely used platform for collaboration and document management. This vulnerability arises from a missing authentication mechanism for critical functions, enabling unauthorized users to elevate their privileges over a network without appropriate permissions. As a result, attackers can gain access to sensitive information and functionalities that could allow them to manipulate data or resources, posing a serious threat to both the integrity and confidentiality of organizational assets. The lack of robust authentication measures in key parts of the application highlights a critical weakness that could be exploited by malicious actors looking to compromise SharePoint environments.

Potential impact of CVE-2026-56164

  1. Unauthorized Data Access: The vulnerability can allow attackers to bypass authentication controls, leading to unauthorized access to sensitive documents and user information stored within SharePoint. This risk can result in data breaches, revealing confidential organizational or personal data to potential misuse.

  2. Privilege Escalation: Attackers exploiting this vulnerability can elevate their privileges, gaining administrative-level access to SharePoint. This can grant them the ability to modify or delete essential data, create unauthorized accounts, and execute harmful actions without detection, severely compromising system security.

  3. Network Compromise: The potential for unauthorized access expands beyond SharePoint itself, as an attacker could leverage this access to move laterally across the network. This can lead to further infiltration into connected systems, potentially enabling more extensive cyberattacks or the deployment of additional malware, including ransomware.

CISA has reported CVE-2026-56164

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-56164 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5561.1001

Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20175

Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.19725.20434

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

SharePoint zero-day grants Farm Admin rights, CISA warns

CISA warns of active exploitation targeting on-premises SharePoint Server, with attackers stealing IIS machine keys to survive patching. See which CVEs are confirmed exploited and how to respond.

4 days ago

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive.

3 weeks ago

CISA urges immediate SharePoint hardening as exploits mount

Three actively exploited SharePoint vulnerabilities have landed in the KEV catalog, with security experts warning that patching alone won’t prevent business disruption.

3 weeks ago

References

EPSS Score

22% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 💰

    Used in Ransomware

  • 🟡

    Public PoC available

  • 📰

    First article discovered by The Hacker News

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.