Skip to content
Auto-CTI
Back to today
KEV NEW CRITICAL B1

Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)

B Rapid7 Cybersecurity Blog · · CVE-2026-55040

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
9.1
EPSS
40%
KEV due date
21 August 2026

Affected versions

sharepoint server sharepoint server 2016 sharepoint server 2019

Key insight

A critical flaw in SharePoint's JWT token validation logic allows attackers to bypass authentication without valid cryptographic signatures.

Description

CVE-2026-55040 is a critical authentication bypass vulnerability in Microsoft SharePoint rooted in multiple JWT token validation flaws. The vulnerability allows an attacker to craft forged JWT tokens that SharePoint will accept, as critical security checks can be disabled or bypassed. Specifically affected are RequireSignedTokens validation, x5t header resolution without signature verification, faulty issuer validation, and a non-cryptographic signature check. Once authentication is bypassed, an attacker gains access to the authenticated attack surface of the target SharePoint deployment and can perform subsequent operations.

Risk score

76
cvss base
91.00
kev bonus
20.00
epss bonus
0.00
poc bonus
15.00
raw before weight
126.00
industry weight
1.21
freshness factor
0.50
exploitability factor
1.00
days old
28.00
vendor mismatch penalty
0.00

Path: operational

ESC