Junglewise Threat Intelligence

CVE-2026-56164: Microsoft SharePoint missing authentication in critical function

CVE-2026-56164 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2026-07-14

Technologies: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server, Microsoft SharePoint Server 2019. Vendors: Microsoft.

Executive brief

Microsoft SharePoint, a widely used platform for document management and team collaboration, contains a security flaw that allows unauthorized users to perform actions they should not be able to. An attacker could exploit this over the network to gain higher-level permissions within the system without needing to log in. This could lead to unauthorized changes to site settings or data, potentially compromising the integrity of corporate information.

Technical details

A vulnerability classified as Missing Authentication for Critical Function (CWE-306) exists in multiple versions of Microsoft SharePoint Server. The flaw allows an unauthenticated attacker to perform actions that should require authorization, leading to a privilege escalation. The attack can be carried out remotely over the network without any user interaction. Microsoft has released updates to address this issue in SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Although the advisory mentions active exploitation in the wild, the CVSS 3.1 score provided by the vendor is 5.3 (Medium).

Affected products

  • Microsoft SharePoint Enterprise Server 2016 16.0.0 to < 16.0.5561.1001
  • Microsoft SharePoint Server 2019 16.0.0 to < 16.0.10417.20175
  • Microsoft SharePoint Server Subscription Edition 16.0.0 to < 16.0.19725.20434

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: exploited: Reported as exploited in the wild at time of publication

Related threats