Junglewise Threat Intelligence

CVE-2026-55051: Microsoft SharePoint SSRF information disclosure

CVE-2026-55051 · Severity: medium · CVSS 6.5 · Published 2026-07-14

Technologies: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019. Vendors: Microsoft.

Executive brief

Microsoft SharePoint, a widely used collaboration and document management platform, is affected by a security vulnerability that could allow an authorized user to access sensitive information. By exploiting this flaw, an attacker with basic user permissions can force the server to make requests to internal systems that are otherwise protected from the outside world. This could lead to the exposure of internal data or configuration details, potentially aiding further attacks on the corporate network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in multiple versions of Microsoft SharePoint Server, including 2016, 2019, and Subscription Edition. The flaw (CWE-918) allows an authenticated attacker with low privileges to submit specially crafted requests that the server then executes. This can be used to probe internal network resources or access metadata services that the SharePoint server has access to but are not directly reachable by the attacker. The vulnerability is exploitable over the network without user interaction, though it does require valid credentials. Microsoft has released security updates to address this issue across the affected versions.

Affected products

  • Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001
  • Microsoft SharePoint Server 2019 16.0.0 to 16.0.10417.20175
  • Microsoft SharePoint Server Subscription Edition 16.0.0 to 16.0.19725.20434

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD

References

Related threats