CVE Tools

Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)

Rapid7 BlogBy Stephen Fewer13 min read

PoC publicSharePoint

Our summary

Rapid7 has published a technical analysis and proof-of-concept exploit for CVE-2026-55040, a critical authentication bypass vulnerability in Microsoft SharePoint. The flaw stems from multiple weaknesses in the JWT token validation pipeline, specifically allowing attackers to disable signature requirements and forge valid tokens using the server's own Security Token Service certificate.

Unauthenticated remote attackers can leverage this issue to impersonate any site user or administrator on SharePoint Server Subscription Edition. Rapid7’s research confirms that the vulnerability is actively exploitable through a public script that demonstrates how to craft malicious Bearer tokens to bypass standard security controls.

Read at Rapid7 Blog

Below is the opening; the full story is at Rapid7 Blog.

From Rapid7 Blog

Overview

On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) CVE-2026-55040">script.…

Continue at Rapid7 Blog

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store