TGViewer
Whitehat Lab Whitehat Lab @wh_lab · 3.17K subscribers
Post #776 960
😥 CVE-2026-55040

Неправильная проверка JWT в SharePoint Server Subscription Edition приводит к произвольному входу в учетную запись

By leveraging CVE-2026-55040, a remote unauthenticated attacker can assume the identity of any SharePoint site user; the prerequisite is the attacker must know in advance the user they wish to identify as. This can be achieved in a number of ways, including via a user’s Active Directory (AD) Security ID (SID), or via a user’s AD User Principal Name (UPN)


🔗 Research
🔗 Rapid7 research
🐱 PoC

#cve #poc #sharepoint #windows #jwt

✈️ Telegram 💬 MAX
  • 🔥 2
  • ❤ 1
More from @wh_lab
  1. Sep 21, 2026🔄🕸 humble v1.66 Быстрый анализатор HTTP заголовков, ориентированный на безопасность В 🐧…
  2. Sep 20, 2026🙂 Лучше вкусного напитка в пятницу может быть только вкусный напиток + доклады с OFFZONE…
  3. Sep 19, 2026💻 CVE-2026-49179: Active Directory WriteSPNScript Command Injection Компонент (ntdsai.dll…
  4. Sep 18, 2026cups2root Linux LPE Interactive root shell from a local account in the lpadmin group.
  5. Sep 18, 2026⚙️ CDP Toolkit Инструмент для работы через Chrome DevTools Protocol (CDP) Beacon Object Fi…
  6. Sep 17, 2026💀 go-responder NTLMv2 hash capture tool in pure Go zero deps, single static binary. Poiso…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →