Jul 2026: Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2026-56164 Published on July 14, 2026

Microsoft SharePoint Server Elevation of Privilege Vulnerability
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Vendor Advisory NVD

Known Exploited Vulnerability

This Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

The following remediation steps are recommended / required by July 17, 2026: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicab

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2026-56164

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 

Affected Versions

Microsoft SharePoint Enterprise Server 2016: Microsoft SharePoint Server 2019: Microsoft SharePoint Server Subscription Edition: