
Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate users, including mass attack mode.
JWT Token Bypass Exploit for Microsoft SharePoint (CVE-2026-55040, CVSS 9.1).
Forge authentication tokens using three attack vectors:
Impersonate any user including administrators. Includes single-target exploitation, automated curl-based attack, and mass attack mode for bulk targets. Python 3 required.