Microsoft Office SharePoint
CVE-2026-56164 — Microsoft SharePoint Server Elevation of Privilege Vulnerability
Executive Summary
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Overview
9.8
CVSS CRITICAL
Moderate
MS Severity
Exploited
MS Exploit Status
Exploitation Detected
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
None
INTEGRITY
Low
AVAILABILITY
None
EXPLOIT CODE MATURITY
Functional
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 4.9
EPSS Score
0.22439
probability of exploitation in the next 30 days
0.97486 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
3 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Microsoft SharePoint Enterprise Server 2016 | 5002891 (Security Update) |
Moderate | Elevation of Privilege | Maybe |
| Microsoft SharePoint Server 2019 | 5002883 (Security Update) |
Moderate | Elevation of Privilege | Maybe |
| Microsoft SharePoint Server Subscription Edition | 5002882 (Security Update) |
Moderate | Elevation of Privilege | Maybe |
Patches
3 patches
| Article | Type | Restart |
|---|---|---|
5002891 |
Security Update | Maybe |
5002883 |
Security Update | Maybe |
5002882 |
Security Update | Maybe |
Exploits & PoC
2 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| sentinel-aidefense/CVE-2026-56164-EXP | 14 | 2026-07-15 | CVE-2026-56164 EOP Exploit |
| sam00/POC-CVE-2026-56164-exploit | 2 | 2026-08-06 | CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated, remote attackers to elevate privileges over a network. |
Detection Rules
No public Sigma or Nuclei detection rule has been mapped to this CVE yet. Coverage is concentrated on exploited / high-profile vulnerabilities; check SigmaHQ for updates.
Acknowledgments
Anonymous
Genwei Jiang with Google Cloud, FLARE OTF
Jayson Frost with Mandiant Incident Response
References
On This Page