CVE-2026-56164
MEDIUM KEVMicrosoft SharePoint Server Elevation of Privilege Vulnerability
Title source: cnaExploitation Summary
CVE-2026-56164 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 14, 2026. EIP tracks 3 public exploits from researchers including WismanSec, sam00, sentinel-aidefense.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-56164, a deserialization vulnerability in SharePoint 2026 that allows remote attackers to dump machine keys or achieve RCE via crafted SecurityContextToken requests to the /_trust endpoint. The exploit leverages ysoserial.net gadgets for .NET deserialization attacks.
Description
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Exploits (3)
This repository contains a functional proof-of-concept exploit for CVE-2026-56164, a deserialization vulnerability in SharePoint 2026 that allows remote attackers to dump machine keys or achieve RCE via crafted SecurityContextToken requests to the /_trust endpoint. The exploit leverages ysoserial.net gadgets for .NET deserialization attacks.
This repository contains a functional exploit for CVE-2026-56164, an authentication bypass vulnerability in Microsoft SharePoint Server. The exploit leverages missing authentication checks in Microsoft.Office.Server.UserProfiles by omitting X-RequestDigest headers and using specific routing headers to escalate privileges to Farm Administrator and execute arbitrary commands.
The repository claims to be an unauthenticated privilege escalation exploit for Microsoft SharePoint Server (CVE-2026-56164) via a crafted SOAP payload, but provides no actual exploit code. Instead, it links to an external download (tinyurl) and uses vague technical descriptions without concrete details.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N