CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability. Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
- CISA KEV-listed (remediation due 2026-07-17)
- EPSS 26.6% (97.9% percentile)
- CVSS 5.3 medium