CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (Unpatched Chain Component, PoC Public) — Threadlinqs Intelligence
As of 2026-07-14, CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (Unpatched Chain Component, PoC Public) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-1341 · Severity: CRITICAL · CVSS: 9.1 · Status: ACTIVE · Category: VULNERABILITY
A weak-authentication flaw in the JWT token validation pipeline of on-premises Microsoft SharePoint (CVE-2026-55040, CVSS 3.1 9.1) lets a remote, unauthenticated attacker who knows a target user's
CVE-2026-55040 is a weak-authentication (CWE-1390) vulnerability in the JWT token validation pipeline used by on-premises Microsoft SharePoint (SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition). Rapid7 Labs researcher Stephen Fewer identified 'several issues in the JWT token validation pipeline' that allow an attacker to forge or manipulate a session JWT without possessing any credentials. Exploitation requires only that the attacker know a target user's Active Directory Security Identifier (SID) or User Principal Name (UPN, an email-formatted identifier) -- both of which are frequently enumerable via OSINT, prior breaches, Microsoft Graph/Entra ID enumeration, or SharePoint's own user-picker/search endpoints. With a forged token, the attacker impersonates that user -- including SharePoint site administrators -- and inherits their full access to document libraries, lists, workflows, and any connected Microsoft 365/on-prem integrations.
The vulnerability originated from an AI-assisted offensive security research project: Rapid7 ran 96 AI research sessions across 24 active days in two sprints (January 2026 and March 2026), generating roughly 80,000 tool calls hunting for a SharePoint remote-code-execution chain suitable for Pwn2Own Berlin 2026. The January sprint failed to produce a working chain; the March sprint identified CVE-2026-55040 and successfully chained it with a second, separate RCE vulnerability to achieve full unauthenticated remote code execution on a vulnerable SharePoint server. Fewer entered the chain at Pwn2Own Berlin 2026 (May 2026) but could not get the exploit working within the competition's allotted time, earning no prize or Master of Pwn points -- the bug was nonetheless real and was reported to Microsoft immediately after.
Rapid7 reported the finding to Microsoft on 2026-05-18; Microsoft confirmed on 2026-05-20 and opted to patch the chain across two separate update cycles rather than hold the fix until both components were ready: the JWT authentication-bypass component (CVE-2026-55040) is scheduled for the July 2026 Patch Tuesday cycle, while the paired RCE component remains unpatched and is expected in the August 2026 cycle. A coordinated-disclosure agreement was finalized on 2026-05-29, and CVE-2026-55040 was publicly disclosed on 2026-07-14 as part of Microsoft's July 2026 Patch Tuesday release (622 CVEs total, a record volume, including two actively-exploited zero-days unrelated to this chain: CVE-2026-56164 and others).
A meaningful discrepancy exists in severity scoring: Rapid7's own advisory and NVD both list CVSS v3.1 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N -- network vector, low complexity, no privileges or user interaction required, high confidentiality and integrity impact, no availability impact), consistent with a full-impersonation authentication bypass. Trend Micro's Zero Day Initiative (ZDI) independently rates the same bug Critical at 9.1, while some secondary summaries have cited Microsoft's own MSRC rating as Medium 5.3 -- a four-point spread that industry commentary (The Hacker News) flagged as illustrative of how unreliable a bare CVSS number can be during a high-volume patch month. Given the network-exploitable, unauthenticated, no-user-interaction nature of the flaw and its role as the first link in a demonstrated unauthenticated-RCE chain, this threat record treats CVE-2026-55040 as Critical severity for defensive prioritization purposes.
Because the authentication-bypass half of the chain is now public (via the Rapid7 blog and this disclosure) while the RCE half remains unpatched until August 2026, a live exploitation window exists: any attacker who reverse-engineers or independently discovers the same RCE component can pair it with the now-public JWT bypass technique for unauthenticated remote code execution against any internet- or intranet-exposed, unpatched on-premises SharePoint server. Microsoft and Rapid7
Target sectors: government administration, finance, health, education, technology, manufacturing, legal
Target regions: North America, Europe, Asia Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-55040, T1190, T1078, T1606, T1550, T1649, T1087, T1482, T1589, T1595, T1078