CVE-2026-56164

MEDIUM KEV

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-56164 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 14, 2026. EIP tracks 3 public exploits from researchers including WismanSec, sam00, sentinel-aidefense.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-56164, a deserialization vulnerability in SharePoint 2026 that allows remote attackers to dump machine keys or achieve RCE via crafted SecurityContextToken requests to the /_trust endpoint. The exploit leverages ysoserial.net gadgets for .NET deserialization attacks.

Description

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Exploits (3)

github WORKING POC
by WismanSec · htmlpoc
https://github.com/WismanSec/sharepoint-2026-poc

This repository contains a functional proof-of-concept exploit for CVE-2026-56164, a deserialization vulnerability in SharePoint 2026 that allows remote attackers to dump machine keys or achieve RCE via crafted SecurityContextToken requests to the /_trust endpoint. The exploit leverages ysoserial.net gadgets for .NET deserialization attacks.

Classification
Working Poc 98%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Microsoft SharePoint 2026 (unspecified version, likely patched in later updates)
No auth needed
Prerequisites: Target must be running a vulnerable version of SharePoint 2026 · Attacker must have network access to the SharePoint /_trust endpoint · ysoserial.net executable must be available for gadget generation · For RCE: PowerShell execution policy must not block the payload (or use --rawcmd variant)
mistral-large-3 · analyzed Aug 07, 2026 Full analysis →
github WORKING POC
by sam00 · pythonpoc
https://github.com/sam00/POC-CVE-2026-56164-exploit

This repository contains a functional exploit for CVE-2026-56164, an authentication bypass vulnerability in Microsoft SharePoint Server. The exploit leverages missing authentication checks in Microsoft.Office.Server.UserProfiles by omitting X-RequestDigest headers and using specific routing headers to escalate privileges to Farm Administrator and execute arbitrary commands.

Classification
Working Poc 98%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Microsoft SharePoint Server 2016, 2019, and Subscription Edition (versions prior to patched builds 16.0.5561.1001, 16.0.10417.20175, and 16.0.19725.20434 respectively)
No auth needed
Prerequisites: Network access to the SharePoint server · Target must be running an unpatched version of SharePoint Server 2016, 2019, or Subscription Edition
mistral-large-3 · analyzed Aug 06, 2026 Full analysis →
github SUSPICIOUS
by sentinel-aidefense · poc
https://github.com/sentinel-aidefense/CVE-2026-56164-EXP

The repository claims to be an unauthenticated privilege escalation exploit for Microsoft SharePoint Server (CVE-2026-56164) via a crafted SOAP payload, but provides no actual exploit code. Instead, it links to an external download (tinyurl) and uses vague technical descriptions without concrete details.

Classification
Suspicious 98%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Unknown
Target: Microsoft SharePoint Server Subscription Edition < 16.0.19725.20434, SharePoint Server 2019 < 16.0.10417.20175, SharePoint Enterprise Server 2016 < 16.0.5561.1001
No auth needed
Prerequisites: Network access to SharePoint Server · Affected version of SharePoint Server
mistral-large-3 · analyzed Jul 15, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory patch
Microsoft SharePoint Server Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164

Scores

CVSS v3 5.3
EPSS 0.2244
EPSS Percentile 97.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact partial

Details

CISA KEV 2026-07-14
VulnCheck KEV 2026-07-14
ENISA EUVD EUVD-2026-44043
CWE
CWE-306
Status published
Products (6)
Microsoft/Microsoft SharePoint Enterprise Server 2016 16.0.0 - 16.0.5561.1001
Microsoft/Microsoft SharePoint Server 2019 16.0.0 - 16.0.10417.20175
Microsoft/Microsoft SharePoint Server Subscription Edition 16.0.0 - 16.0.19725.20434
microsoft/sharepoint_server 2016
microsoft/sharepoint_server 2019
microsoft/sharepoint_server < 16.0.19725.20434
Published Jul 14, 2026
KEV Added Jul 14, 2026
Tracked Since Jul 14, 2026