Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-55040-Mass-Exploit — Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate users, including mass attack mode. | Kitploit
Tools/GitHubGitHub/maxprog-svg/cve-2026-55040-mass-exploit
Authentication & AuthorizationPayload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubmaxprog-svg/cve-2026-55040-mass-exploit

CVE-2026-55040-Mass-Exploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate users, including mass attack mode.

View Repository
331 month agoNot yet reviewed

JWT Token Bypass Exploit for Microsoft SharePoint (CVE-2026-55040, CVSS 9.1).

Forge authentication tokens using three attack vectors:

  • Algorithm "none" (skips signature verification)
  • Weak HS256 secrets (with brute-force dictionary support)
  • RS256 key substitution

Impersonate any user including administrators. Includes single-target exploitation, automated curl-based attack, and mass attack mode for bulk targets. Python 3 required.

https://satoshidisk.com/pay/CSGDgs

Download Tool