CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
Other sources
Microsoft SharePoint Server Security Feature Bypass Vulnerability
— Microsoft
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1001Patch KB5002891 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20434Patch KB5002882 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20175Patch KB5002883
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55040?
CVE-2026-55040 has a severity rating of 9.1, categorized as critical.
How do I fix CVE-2026-55040?
To fix CVE-2026-55040, apply the available patch provided by Microsoft for affected SharePoint Server versions.
What impact does CVE-2026-55040 have on Microsoft SharePoint Server?
CVE-2026-55040 allows unauthorized attackers to bypass security features due to weak authentication.
Which versions of Microsoft SharePoint are affected by CVE-2026-55040?
CVE-2026-55040 affects Microsoft SharePoint Server, SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
When was CVE-2026-55040 published?
CVE-2026-55040 was published on July 14, 2026.