Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
POC-CVE-2026-56164-exploit — CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated, remote attackers to elevate privileges over a network. | Kitploit
Tools/GitHubGitHub/sam00/poc-cve-2026-56164-exploit
Authentication & AuthorizationPrivilege EscalationVulnerability ScannersPayload GenerationExploitationWeb Application ExploitationInformation GatheringPenetration Testing

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubsam00/poc-cve-2026-56164-exploit

POC-CVE-2026-56164-exploit

CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated, remote attackers to elevate privileges over a network.

View Repository
2141 month agoNot yet reviewed

CVE-2026-56164 — Microsoft SharePoint Server Authentication Bypass Exploit

Critical (CVSS 9.8) — Unauthenticated Privilege Escalation to Farm Administrator in Microsoft SharePoint Server

Table of Contents

  • Overview
  • Vulnerability Details
  • Affected Versions
  • Architecture Diagrams
  • Project Structure
  • Installation
  • Scanner Usage — Step by Step
  • Exploit Usage — Step by Step
  • Payload Design
  • Mitigation
  • Disclaimer

Overview

CVE-2026-56164 is a critical missing authentication vulnerability in Microsoft SharePoint Server that allows an unauthenticated remote attacker to elevate privileges to Farm Administrator level. The vulnerability resides in the Microsoft.Office.Server.UserProfiles assembly which processes SOAP requests at /_vti_bin/client.svc/ProcessQuery.

By intentionally omitting the X-RequestDigest header and supplying specific routing headers, the vulnerable server falls back to an elevated security context instead of rejecting the unauthenticated request. This allows anonymous attackers to enumerate site collections, users, farm configuration, add administrators, and execute commands.

CISA KEV: This vulnerability is listed in CISA's Known Exploited Vulnerabilities Catalog due to active exploitation in the wild.


Vulnerability Details

FieldValue
CVE IDCVE-2026-56164
SeverityCRITICAL
CVSS 3.19.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CWECWE-306: Missing Authentication for Critical Function
ImpactUnauthenticated Elevation of Privilege to Farm Administrator
Exploitation StatusActive exploitation (CISA KEV)
MITRE ATT&CKT1190 (Exploit Public-Facing Application)

Root Cause

The Microsoft.Office.Server.UserProfiles handler processes SOAP requests at /_vti_bin/client.svc/ProcessQuery. Under normal operations, SharePoint validates the X-RequestDigest header to assert authentication context. However, a validation bypass exists:

  1. If X-RequestDigest is absent AND specific routing headers are present
  2. The system evaluates routing parameters and falls back to a highly privileged default state
  3. The request is processed with system-level credentials instead of the caller's security context

Vulnerable Code Path

// Vulnerable: If digest is missing, handler checks routing headers
if (string.IsNullOrEmpty(digest) && CheckSpecialRoutingHeaders(context)) {
    // Bypasses standard identity validation → elevated admin session
    InitializeElevatedSecurityContext(context);
} else {
    ValidateRequestDigest(digest);  // Normal path
}

Patched Code

// Patched: Digest validation is unconditional
if (string.IsNullOrEmpty(digest)) {
    context.Response.StatusCode = 401;
    throw new UnauthorizedAccessException("Missing request digest.");
}
ValidateRequestDigest(digest);
InitializeStandardSecurityContext(context);

Advisory References

  • MSRC: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56164
  • CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56164

Affected Versions

ProductAffected VersionsPatched Version
SharePoint Enterprise Server 2016All 16.0.x prior to patch16.0.5561.1001
SharePoint Server 2019All 16.0.x prior to patch16.0.10417.20175
SharePoint Server Subscription EditionAll 16.0.x prior to patch16.0.19725.20434

Not impacted: SharePoint Online (Microsoft 365)


Architecture Diagrams

System Architecture

┌─────────────────────────────────────────────────────────────────────┐
│                   CVE-2026-56164 Exploit Toolkit                     │
├─────────────────────────────────────────────────────────────────────┤
│                                                                      │
│  ┌────────────┐     ┌─────────────────┐     ┌────────────────────┐  │
│  │  scan.py   │────▶│  HTTP Fingerprint│     │  payload_gen.py    │  │
│  │  Scanner   │     │  + Version Check │     │                    │  │
│  └────────────┘     └─────────────────┘     │  ┌──────────────┐  │  │
│         │                                   │  │ CSOM Payloads│  │  │
│         │  Reports:                         │  │ (detection,  │  │  │
│         │  • SharePoint detected?           │  │  enum,       │  │  │
│         │  • Server version                 │  │  elevate,    │  │  │
│         │  • Vulnerable?                    │  │  execute)    │  │  │
│         │  • Auth bypass confirmed?         │  └──────────────┘  │  │
│         ▼                                   │  ┌──────────────┐  │  │
│  ┌────────────┐     ┌─────────────────┐     │  │ SOAP Payloads│  │  │
│  │ exploit.py │────▶│  HTTP Request   │     │  │ (admin, exec)│  │  │
│  │  Exploit   │     │  Delivery       │     │  └──────────────┘  │  │
│  └────────────┘     └─────────────────┘     │  ┌──────────────┐  │  │
│         │                                   │  │ Bypass       │  │  │
│         │  ┌──────────────────────┐         │  │ Headers      │  │  │
│         ├─▶│ MODE: detect         │         │  │ (routing)    │  │  │
│         │  │ Safe, non-intrusive  │         │  └──────────────┘  │  │
│         │  └──────────────────────┘         │  ┌──────────────┐  │  │
│         │  ┌──────────────────────┐         │  │ HTTP Request │  │  │
│         ├─▶│ MODE: enumerate      │         │  │ Builder      │  │  │
│         │  │ Sites, users, config │         │  └──────────────┘  │  │
│         │  └──────────────────────┘         └────────────────────┘  │
│         │  ┌──────────────────────┐                                 │
│         ├─▶│ MODE: elevate        │     ┌──────────────────────┐    │
│         │  │ Add site/farm admin  │     │ Target SharePoint    │    │
│         │  └──────────────────────┘     │ /_vti_bin/client.svc │    │
│         │  ┌──────────────────────┐     │ /_vti_bin/SPAdmin    │    │
│         └─▶│ MODE: execute        │     └──────────────────────┘    │
│            │ System commands      │                                 │
│            └──────────────────────┘                                 │
│         │  ┌──────────────────────┐                                 │
│         └─▶│ MODE: full           │  detect→enum→elevate→execute    │
│            └──────────────────────┘                                 │
└─────────────────────────────────────────────────────────────────────┘

Scanner Flow

Download Tool