Overview
What is CVE-2026-56164?
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
CISA lists CVE-2026-56164 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Microsoft SharePoint Server.
Public exploit: Not collected. Review the linked vendor advisory and apply the mitigation or fixed release for your affected product.
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.