type: cve ยท created: 2026-08-27 ยท updated: 2026-08-27 ยท tags: [cve, authentication-bypass, kev, sharepoint] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, government, education] ยท au_impact: true
CVE-2026-55040 โ SharePoint JWT Token Authentication Bypass
CVE-2026-55040 is an authentication-bypass flaw in the JWT token validation pipeline of Microsoft SharePoint Server, letting an unprivileged attacker operate as a site user or admin. It forms the first half of a chain with the Business Connectivity Services RCE CVE-2026-63520. CISA ordered federal patching on 18 August.
Type: JWT authentication bypass | Exploitation: actively targeted, chained | Mitigation: apply patch; do not expose SharePoint directly