Executive brief
Microsoft SharePoint is a widely-deployed collaboration and document management platform used by many organizations. This authentication weakness allows attackers to gain unauthorized access to SharePoint instances over the network without valid credentials, potentially exposing sensitive business documents, customer data, and internal communications. Active exploitation has been observed in the wild.
Technical details
This vulnerability is an authentication bypass in Microsoft SharePoint that allows unauthorized access over the network without proper credential validation. The weak authentication mechanism enables attackers to circumvent security controls and gain access to the SharePoint environment. The vulnerability is network-reachable and does not require prior authentication or user interaction to exploit. An attacker can leverage this flaw to access sensitive data, modify content, or establish persistence within the SharePoint infrastructure. The vulnerability has been actively exploited in the wild as of the publication date.
Affected products
- Microsoft SharePoint
Timeline
- 2026-08-18: disclosed
- 2026-08-18: exploited