Crypto Ticker:
sysadmin from Cyber Security News

Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Abinaya
5 hours ago
2 Views
0 Comments
Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Two serious Microsoft SharePoint Server vulnerabilities can be chained to let remote attackers take control of vulnerable servers without a password. The attack combines an authentication bypass tracked as 78 with a remote code execution flaw, CVE-2026-63520. CVE-2026-55040, rated 9.1 out of 10 under CVSS v3.1, affects SharePoint’s JSON Web Token, or JWT, authentication handler. The flaw allows an unauthenticated attacker to forge a token and impersonate a SharePoint user if they know that user’s security identifier or user principal name, such as user@domain. The issue exists because multiple JWT security checks in SharePoint’s token validation process were disabled or insufficient. Rapid7 researchers found that the...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!