Junglewise Threat Intelligence

CVE-2026-55052: Microsoft SharePoint privilege escalation via missing authorization

CVE-2026-55052 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019. Vendors: Microsoft.

Executive brief

Microsoft SharePoint is a widely used collaboration and document management platform for businesses. A security flaw in the system's authorization checks allows an existing user with low-level access to gain higher-level administrative privileges. This could lead to unauthorized access to sensitive corporate data, modification of site content, or a total loss of control over the SharePoint environment.

Technical details

A privilege escalation vulnerability exists in Microsoft SharePoint Server due to missing authorization checks (CWE-862). An attacker must be authenticated to the target environment with at least low-privileged user permissions to exploit this flaw. By sending specially crafted network requests to a vulnerable SharePoint instance, the attacker can bypass intended access controls to gain elevated permissions. Successful exploitation grants the attacker high-impact access to confidentiality, integrity, and availability of the server. Affected versions include SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.

Affected products

  • Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
  • Microsoft SharePoint Server 2019 < 16.0.10417.20175
  • Microsoft SharePoint Server Subscription Edition < 16.0.19725.20434

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats