Description
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-07-14
Score: 5.3 Medium
EPSS: 22.4% Moderate
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authentication for a critical function in Microsoft SharePoint Server allows an attacker to invoke that function without credentials, enabling privilege escalation. The vulnerability is a CWE‑306 type authentication bypass and can let an unauthorized user perform administrative actions normally reserved for privileged accounts.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are all affected. All releases of these products remain vulnerable until a patch is applied, as no narrower version range has been disclosed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of 22 % suggests a significant likelihood that attackers will target this flaw. It is listed in the CISA KEV catalog, confirming real‑world exploitation. Based on the description, the vulnerable function can be accessed remotely over a network; an attacker who can reach the SharePoint server can exploit the flaw from within the same domain without prior authentication.

Generated by OpenCVE AI on August 4, 2026 at 18:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update released by Microsoft for CVE‑2026‑56164.
  • Restrict access to the vulnerable function, limiting it to trusted administrators or disabling it if not required.
  • Enforce least‑privilege permissions on SharePoint users and services to reduce the impact of a potential privilege escalation.

Generated by OpenCVE AI on August 4, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-07-14T00:00:00+00:00', 'dueDate': '2026-07-17T00:00:00+00:00'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft SharePoint Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-306
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:32.361Z

Reserved: 2026-06-19T13:53:31.988Z

Link: CVE-2026-56164

cve-icon Vulnrichment

Updated: 2026-07-14T17:32:39.759Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:45:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function