
CVE-2026-56164 è una vulnerabilità critica di mancata autenticazione che colpisce Microsoft SharePoint Server on-premises. Consente ad attaccanti remoti non autenticati di elevare i privilegi attraverso la rete.
Critico (CVSS 9.8) — Escalation di privilegi non autenticata ad Amministratore Farm in Microsoft SharePoint Server
CVE-2026-56164 è una vulnerabilità critica di autenticazione mancante in Microsoft SharePoint Server che consente a un utente remoto non autenticato di elevare i propri privilegi fino al livello di Amministratore Farm. La vulnerabilità risiede nell'assembly Microsoft.Office.Server.UserProfiles, che elabora le richieste SOAP all'indirizzo /_vti_bin/client.svc/ProcessQuery.
Omettendo intenzionalmente l'header X-RequestDigest e fornendo specifici header di routing, il server vulnerabile ripiega su un contesto di sicurezza elevato invece di rifiutare la richiesta non autenticata. Ciò consente ad attaccanti anonimi di enumerare raccolte siti, utenti e configurazione della farm, aggiungere amministratori ed eseguire comandi.
CISA KEV: questa vulnerabilità è elencata nel catalogo Known Exploited Vulnerabilities di CISA a causa dello sfruttamento attivo in ambiente reale.
| Campo | Valore |
|---|---|
| CVE ID | CVE-2026-56164 |
| Gravità | CRITICO |
| CVSS 3.1 | 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
| CWE | CWE-306: Mancata autenticazione per funzioni critiche |
| Impatto | Elevazione di privilegi non autenticata ad Amministratore Farm |
| Stato dello sfruttamento | Sfruttamento attivo (CISA KEV) |
| MITRE ATT&CK | T1190 (Exploit Public-Facing Application) |
Il gestore Microsoft.Office.Server.UserProfiles elabora le richieste SOAP all'indirizzo /_vti_bin/client.svc/ProcessQuery. In condizioni normali, SharePoint valida l'header X-RequestDigest per accertare il contesto di autenticazione. Tuttavia, esiste un bypass di validazione:
X-RequestDigest è assente E sono presenti specifici header di routing// Vulnerable: If digest is missing, handler checks routing headers
if (string.IsNullOrEmpty(digest) && CheckSpecialRoutingHeaders(context)) {
// Bypasses standard identity validation → elevated admin session
InitializeElevatedSecurityContext(context);
} else {
ValidateRequestDigest(digest); // Normal path
}
// Patched: Digest validation is unconditional
if (string.IsNullOrEmpty(digest)) {
context.Response.StatusCode = 401;
throw new UnauthorizedAccessException("Missing request digest.");
}
ValidateRequestDigest(digest);
InitializeStandardSecurityContext(context);
| Prodotto | Versioni interessate | Versione corretta |
|---|---|---|
| SharePoint Enterprise Server 2016 | Tutte le 16.0.x precedenti alla patch | 16.0.5561.1001 |
| SharePoint Server 2019 | Tutte le 16.0.x precedenti alla patch | 16.0.10417.20175 |
| SharePoint Server Subscription Edition | Tutte le 16.0.x precedenti alla patch | 16.0.19725.20434 |
Non interessate: SharePoint Online (Microsoft 365)
┌─────────────────────────────────────────────────────────────────────┐
│ CVE-2026-56164 Exploit Toolkit │
├─────────────────────────────────────────────────────────────────────┤
│ │
│ ┌────────────┐ ┌─────────────────┐ ┌────────────────────┐ │
│ │ scan.py │────▶│ HTTP Fingerprint│ │ payload_gen.py │ │
│ │ Scanner │ │ + Version Check │ │ │ │
│ └────────────┘ └─────────────────┘ │ ┌──────────────┐ │ │
│ │ │ │ CSOM Payloads│ │ │
│ │ Reports: │ │ (detection, │ │ │
│ │ • SharePoint detected? │ │ enum, │ │ │
│ │ • Server version │ │ elevate, │ │ │
│ │ • Vulnerable? │ │ execute) │ │ │
│ │ • Auth bypass confirmed? │ └──────────────┘ │ │
│ ▼ │ ┌──────────────┐ │ │
│ ┌────────────┐ ┌─────────────────┐ │ │ SOAP Payloads│ │ │
│ │ exploit.py │────▶│ HTTP Request │ │ │ (admin, exec)│ │ │
│ │ Exploit │ │ Delivery │ │ └──────────────┘ │ │
│ └────────────┘ └─────────────────┘ │ ┌──────────────┐ │ │
│ │ │ │ Bypass │ │ │
│ │ ┌──────────────────────┐ │ │ Headers │ │ │
│ ├─▶│ MODE: detect │ │ │ (routing) │ │ │
│ │ │ Safe, non-intrusive │ │ └──────────────┘ │ │
│ │ └──────────────────────┘ │ ┌──────────────┐ │ │
│ │ ┌──────────────────────┐ │ │ HTTP Request │ │ │
│ ├─▶│ MODE: enumerate │ │ │ Builder │ │ │
│ │ │ Sites, users, config │ │ └──────────────┘ │ │
│ │ └──────────────────────┘ └────────────────────┘ │
│ │ ┌──────────────────────┐ │
│ ├─▶│ MODE: elevate │ ┌──────────────────────┐ │
│ │ │ Add site/farm admin │ │ Target SharePoint │ │
│ │ └──────────────────────┘ │ /_vti_bin/client.svc │ │
│ │ ┌──────────────────────┐ │ /_vti_bin/SPAdmin │ │
│ └─▶│ MODE: execute │ └──────────────────────┘ │
│ │ System commands │ │
│ └──────────────────────┘ │
│ │ ┌──────────────────────┐ │
│ └─▶│ MODE: full │ detect→enum→elevate→execute │
│ └──────────────────────┘ │
└─────────────────────────────────────────────────────────────────────┘