AI-Powered Attack Chain Exposes Vulnerability in SharePoint Servers
Security researchers have discovered a way to exploit Microsoft SharePoint servers using an AI-assisted attack chain. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), allows an unauthenticated attacker to assume any user's identity, including that of an administrator.
The vulnerability affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft has not released a patch for this issue yet, but Rapid7 says the July update breaks the chain, making it more difficult for attackers to exploit the flaw.
Rapid7 used an AI agent to find the vulnerability in March 2026, after two research sprints against the SharePoint codebase. The firm's proof-of-concept queries the target's domain controller to enumerate users by SID, then uses the bypass until it identifies the site administrator.