{"@odata.context":"https://api.msrc.microsoft.com/sug/v2.0/sugodata/v2.0/en-US/$metadata#vulnerability/$entity","id":"00000000-0000-0000-0000-000076b331b5","releaseDate":"2026-07-14T07:00:00-07:00","cveNumber":"CVE-2026-56164","cveTitle":"Microsoft SharePoint Server Elevation of Privilege Vulnerability","releaseNumber":"2026-Jul","vulnType":"Security Vulnerability","latestRevisionDate":"2026-07-14T07:00:00-07:00","description":"<p>Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.</p>\n","cweList":["CWE-306: Missing Authentication for Critical Function"],"cweDetailsListForSearch":["cwe: CWE-306: Missing Authentication for Critical Function","cweUrl: https://cwe.mitre.org/data/definitions/306.html"],"unformattedDescription":"Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.","mitreText":"CVE-2026-56164","mitreUrl":"https://www.cve.org/CVERecord?id=CVE-2026-56164","publiclyDisclosed":"No","exploited":"Yes","latestSoftwareReleaseId":0,"latestSoftwareRelease":"Exploitation Detected","olderSoftwareReleaseId":0,"denialOfService":"N/A","tag":"Microsoft Office SharePoint","issuingCna":"Microsoft","issuingCnaId":100000001,"severityId":100000002,"severity":"Moderate","impactId":100000002,"impact":"Elevation of Privilege","langCode":"en-US","baseScore":"5.3","temporalScore":"4.9","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:O/RC:C","vectorStringSource":"Microsoft","isMariner":false,"customerActionRequired":true,"customerActionRequiredId":1,"cweDetailsList":[{"keys":["cwe","cweUrl"],"values":["CWE-306: Missing Authentication for Critical Function","https://cwe.mitre.org/data/definitions/306.html"]}],"articles":[{"articleType":"FAQ","description":"<p><strong>According to the CVSS metric, the attack vector is network (AV:N) and the attack complexity is low (AC:L). What does that mean for this vulnerability?</strong></p>\n<p>The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.</p>\n","ordinal":10000},{"title":"Microsoft Office SharePoint Elevation of Privilege Vulnerability","articleType":"100000000","description":"<p>Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.</p>\n","ordinal":10000},{"articleType":"Mitigation","description":"<p><strong>The following <a href=\"https://technet.microsoft.com/library/security/dn848375.aspx#Mitigation\">mitigating factors</a> might be helpful in your situation:</strong></p>\n<p>Enable AMSI: Ensure the Antimalware Scan Interface (AMSI) is actively integrated and scanning SharePoint and IIS worker process memory. Enable AMSI scan feature and set the Request Body Scan mode to Full in order for POST body payloads to be detected.</p>\n<p>Configure AMSI integration with SharePoint Server - <a href=\"https://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/configure-amsi-integration\">https://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/configure-amsi-integration</a></p>\n","ordinal":10000},{"articleType":"FAQ","description":"<p><strong>I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?</strong></p>\n<p>Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.</p>\n","ordinal":10000}],"revisions":[{"cveNumber":"CVE-2026-56164","version":1,"revisionDate":"2026-07-14T07:00:00-07:00","initialDate":"0001-01-01T00:00:00Z","description":"<p>Information published.</p>\n","unformattedDescription":"Information published.","notificationNeeded":false,"notificationSent":false,"sourceId":"2455a6ec-966e-f111-93a1-000d3ac5fb71"}]}