CVE Research
sekurity-team
InSEKurity of the Week (CW34/2026): Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040)
Four separate failures in SharePoint's JWT validation pipeline let an unauthenticated attacker forge a token for any user -- including a site administrator -- and CISA added it to the KEV catalog on August 18 after exploitation followed the public PoC within a day.
Exploit
01
