Recently, security researchers employed artificial intelligence to uncover a significant vulnerability in Microsoft SharePoint servers, allowing unauthorized access as any user, including administrators. This breach affects the SharePoint Server Subscription Edition, as well as the 2019 and 2016 versions, with SharePoint Online remaining unaffected.
Understanding the AI-Driven Exploit
The vulnerability, identified as CVE-2026-55040 with a CVSS score of 9.1, enables attackers to impersonate a specified user by knowing their Active Directory security identifier (SID) or user principal name (UPN). This discovery was pivotal in linking it to another flaw, CVE-2026-63520, which allows remote code execution without credentials.
Through this chain of vulnerabilities, the attackers can execute code as the Windows service account. This issue impacts not only the SharePoint Subscription editions but also Project Server 2013 and Office Web Apps 2013, indicating a broader threat landscape.
Response and Mitigation Efforts
Rapid7, the firm behind this discovery, announced that while a fix is available, Microsoft’s update history had not yet listed an August package at the time of reporting. Users are advised to ensure the installation of the July update, which purportedly disrupts the exploit chain, and to apply the upcoming August update when released.
The bypass occurs within SharePoint’s JSON Web Token (JWT) validation, enabling unauthorized actions. Rapid7’s proof-of-concept includes a script that identifies users by SID, demonstrating the potential for significant exploitation if not addressed promptly.
Broader Implications and Future Outlook
The discovery highlights the necessity for ongoing vigilance and the integration of AI in cybersecurity efforts. Rapid7’s research emphasized that while automation played a crucial role, human oversight was essential to guide AI processes effectively, mitigating inaccurate outcomes.
Moreover, with the end-of-support for SharePoint Server 2016 and 2019, organizations using these versions face increased risk. The continuation of support and updates for these products remains uncertain, emphasizing the importance of proactive security measures.
As vulnerabilities persist, organizations are urged to prioritize security updates and remain alert to potential threats. The use of AI in uncovering such vulnerabilities can significantly enhance detection capabilities, but it must be complemented by expert supervision to ensure robust defenses.
