← Back to browse · API

CVE-2026-56164

Severity
MEDIUM
CVSS
5.3
EPSS
0.22439
Risk score
54.05
CISA KEV
Yes
PoC
Yes
Published
2026-07-14
Modified
2026-08-07
First seen
2026-08-07
Aliases
EUVD-2026-44043, GHSA-HC2F-R46J-4W6X
Products
Microsoft:Microsoft SharePoint Enterprise Server 2016 16.0.0 <16.0.5561.1001, Microsoft:Microsoft SharePoint Server 2019 16.0.0 <16.0.10417.20175, Microsoft:Microsoft SharePoint Server Subscription Edition 16.0.0 <16.0.19725.20434, Microsoft:SharePoint Server
Sources
cisa.gov CVE-2026-56164
github b1a4b47e2e6a108ceda87100|CVE-2026-56164
github be991688bb91f42ffed0b36c|CVE-2026-56164
euvd EUVD-2026-44043

Description

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

References