CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Other sources
Microsoft SharePoint Server Elevation of Privilege Vulnerability
— Microsoft
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5561.1001Patch KB5002891 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20434Patch KB5002882 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20175Patch KB5002883
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56164?
The severity of CVE-2026-56164 is critical, with a CVSS score of 9.8.
How do I fix CVE-2026-56164?
To fix CVE-2026-56164, apply the latest security updates provided by Microsoft for affected SharePoint products.
What type of vulnerability is CVE-2026-56164?
CVE-2026-56164 is an elevation of privilege vulnerability due to missing authentication for critical functions.
Who is affected by CVE-2026-56164?
CVE-2026-56164 affects users of Microsoft SharePoint Server, SharePoint Server Subscription Edition, SharePoint Enterprise Server 2016, and SharePoint Server 2019.
Is CVE-2026-56164 actively exploited in the wild?
Yes, CVE-2026-56164 is listed as a known exploited vulnerability.