Jul 2026: Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2026-56164 Published on July 14, 2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Known Exploited Vulnerability
This Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
The following remediation steps are recommended / required by July 17, 2026: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicab
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-56164
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft SharePoint Enterprise Server 2016:- Version 16.0.0 and below 16.0.5561.1001 is affected.
- Version 16.0.0 and below 16.0.10417.20175 is affected.
- Version 16.0.0 and below 16.0.19725.20434 is affected.