Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

CVE-2026-56164: SharePoint Server lets attackers gain higher privileges

CVE-2026-56164 · published 2 months ago · actively exploited
Summary

SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition contain a missing check that can let an unauthorized user increase their access rights across the network. This could expose confidential data or allow changes to be made without permission. Install the latest updates from Microsoft and verify that only trusted users have administrative privileges.

What to do
  • Update microsoft microsoft sharepoint enterprise server 2016 to version 16.0.5561.1001 or later.
  • Update microsoft microsoft sharepoint server 2019 to version 16.0.10417.20175 or later.
  • Update microsoft microsoft sharepoint server subscription edition to version 16.0.19725.20434 or later.
  • Update microsoft sharepoint_server to version 16.0.19725.20434 or later.
Affected software
VendorProductAffected versions
microsoft microsoft sharepoint enterprise server 2016 < 16.0.5561.1001
microsoft microsoft sharepoint server 2019 < 16.0.10417.20175
microsoft microsoft sharepoint server subscription edition < 16.0.19725.20434
microsoft sharepoint server All versions
microsoft sharepoint_server < 16.0.19725.20434
2016
2019
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Original advisory text
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Severity
5.3 Medium
CVSS 3.1: 5.3 (MITRE)
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS 1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published14 Jul 2026
Updated25 Sep 2026
First seen14 Jul 2026
Sources
CVE-2026-56164 · MITRE
CVE-2026-56164 · CISA KEV
Track software like this
Free during beta