Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-55040-Mass-Exploit — Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate users, including mass attack mode. | Kitploit
Tools/GitHubGitHub/maxprog-svg/cve-2026-55040-mass-exploit
Authentication & AuthorizationPayload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubmaxprog-svg/cve-2026-55040-mass-exploit

CVE-2026-55040-Mass-Exploit

Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate users, including mass attack mode.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
7h 36m agoNot yet reviewed

JWT Token Bypass Exploit for Microsoft SharePoint (CVE-2026-55040, CVSS 9.1).

Forge authentication tokens using three attack vectors:

  • Algorithm "none" (skips signature verification)
  • Weak HS256 secrets (with brute-force dictionary support)
  • RS256 key substitution

Impersonate any user including administrators. Includes single-target exploitation, automated curl-based attack, and mass attack mode for bulk targets. Python 3 required.

https://satoshidisk.com/pay/CSGDgs

Download Tool