
CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated, remote attackers to elevate privileges over a network.
Critical (CVSS 9.8) — Unauthenticated Privilege Escalation to Farm Administrator in Microsoft SharePoint Server
CVE-2026-56164 is a critical missing authentication vulnerability in Microsoft SharePoint Server that allows an unauthenticated remote attacker to elevate privileges to Farm Administrator level. The vulnerability resides in the Microsoft.Office.Server.UserProfiles assembly which processes SOAP requests at /_vti_bin/client.svc/ProcessQuery.
By intentionally omitting the X-RequestDigest header and supplying specific routing headers, the vulnerable server falls back to an elevated security context instead of rejecting the unauthenticated request. This allows anonymous attackers to enumerate site collections, users, farm configuration, add administrators, and execute commands.
CISA KEV: This vulnerability is listed in CISA's Known Exploited Vulnerabilities Catalog due to active exploitation in the wild.
| Field | Value |
|---|---|
| CVE ID | CVE-2026-56164 |
| Severity | CRITICAL |
| CVSS 3.1 | 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
| CWE | CWE-306: Missing Authentication for Critical Function |
| Impact | Unauthenticated Elevation of Privilege to Farm Administrator |
| Exploitation Status | Active exploitation (CISA KEV) |
| MITRE ATT&CK | T1190 (Exploit Public-Facing Application) |
The Microsoft.Office.Server.UserProfiles handler processes SOAP requests at /_vti_bin/client.svc/ProcessQuery. Under normal operations, SharePoint validates the X-RequestDigest header to assert authentication context. However, a validation bypass exists:
X-RequestDigest is absent AND specific routing headers are present// Vulnerable: If digest is missing, handler checks routing headers
if (string.IsNullOrEmpty(digest) && CheckSpecialRoutingHeaders(context)) {
// Bypasses standard identity validation → elevated admin session
InitializeElevatedSecurityContext(context);
} else {
ValidateRequestDigest(digest); // Normal path
}
// Patched: Digest validation is unconditional
if (string.IsNullOrEmpty(digest)) {
context.Response.StatusCode = 401;
throw new UnauthorizedAccessException("Missing request digest.");
}
ValidateRequestDigest(digest);
InitializeStandardSecurityContext(context);
| Product | Affected Versions | Patched Version |
|---|---|---|
| SharePoint Enterprise Server 2016 | All 16.0.x prior to patch | 16.0.5561.1001 |
| SharePoint Server 2019 | All 16.0.x prior to patch | 16.0.10417.20175 |
| SharePoint Server Subscription Edition | All 16.0.x prior to patch | 16.0.19725.20434 |
Not impacted: SharePoint Online (Microsoft 365)
┌─────────────────────────────────────────────────────────────────────┐
│ CVE-2026-56164 Exploit Toolkit │
├─────────────────────────────────────────────────────────────────────┤
│ │
│ ┌────────────┐ ┌─────────────────┐ ┌────────────────────┐ │
│ │ scan.py │────▶│ HTTP Fingerprint│ │ payload_gen.py │ │
│ │ Scanner │ │ + Version Check │ │ │ │
│ └────────────┘ └─────────────────┘ │ ┌──────────────┐ │ │
│ │ │ │ CSOM Payloads│ │ │
│ │ Reports: │ │ (detection, │ │ │
│ │ • SharePoint detected? │ │ enum, │ │ │
│ │ • Server version │ │ elevate, │ │ │
│ │ • Vulnerable? │ │ execute) │ │ │
│ │ • Auth bypass confirmed? │ └──────────────┘ │ │
│ ▼ │ ┌──────────────┐ │ │
│ ┌────────────┐ ┌─────────────────┐ │ │ SOAP Payloads│ │ │
│ │ exploit.py │────▶│ HTTP Request │ │ │ (admin, exec)│ │ │
│ │ Exploit │ │ Delivery │ │ └──────────────┘ │ │
│ └────────────┘ └─────────────────┘ │ ┌──────────────┐ │ │
│ │ │ │ Bypass │ │ │
│ │ ┌──────────────────────┐ │ │ Headers │ │ │
│ ├─▶│ MODE: detect │ │ │ (routing) │ │ │
│ │ │ Safe, non-intrusive │ │ └──────────────┘ │ │
│ │ └──────────────────────┘ │ ┌──────────────┐ │ │
│ │ ┌──────────────────────┐ │ │ HTTP Request │ │ │
│ ├─▶│ MODE: enumerate │ │ │ Builder │ │ │
│ │ │ Sites, users, config │ │ └──────────────┘ │ │
│ │ └──────────────────────┘ └────────────────────┘ │
│ │ ┌──────────────────────┐ │
│ ├─▶│ MODE: elevate │ ┌──────────────────────┐ │
│ │ │ Add site/farm admin │ │ Target SharePoint │ │
│ │ └──────────────────────┘ │ /_vti_bin/client.svc │ │
│ │ ┌──────────────────────┐ │ /_vti_bin/SPAdmin │ │
│ └─▶│ MODE: execute │ └──────────────────────┘ │
│ │ System commands │ │
│ └──────────────────────┘ │
│ │ ┌──────────────────────┐ │
│ └─▶│ MODE: full │ detect→enum→elevate→execute │
│ └──────────────────────┘ │
└─────────────────────────────────────────────────────────────────────┘