{"id":242576,"date":"2026-08-12T05:16:45","date_gmt":"2026-08-12T10:16:45","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/08\/researchers-disclose-aiassisted-sharepoint-exploit-chain-reaching-unauthenticated-rce"},"modified":"2026-08-12T05:16:45","modified_gmt":"2026-08-12T10:16:45","slug":"researchers-disclose-aiassisted-sharepoint-exploit-chain-reaching-unauthenticated-rce","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/08\/researchers-disclose-aiassisted-sharepoint-exploit-chain-reaching-unauthenticated-rce","title":{"rendered":"Researchers Disclose AIAssisted SharePoint Exploit Chain Reaching Unauthenticated RCE"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/researchers-disclose-aiassisted-sharepoint-exploit-chain-reaching-unauthenticated-rce.jpg\"><\/a><\/p>\n<p>The flaw, tracked as <strong>CVE-2026\u201355040<\/strong> (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft\u2019s affected-product list covers only those three on-premises editions, and SharePoint Online is not among them.<\/p>\n<p>It lets a remote unauthenticated attacker assume a chosen user\u2019s identity. The attack has one prerequisite: the intruder has to know which account they want to become, either by its Active Directory security identifier (SID) or its user principal name (UPN), which is formatted like an email address.<\/p>\n<p>Rapid7 then chained the bypass to a separate remote code execution flaw and ran code on the server with no credentials. Microsoft and the firm disclosed that second flaw on August 11 as <strong>CVE-2026\u201363520<\/strong> (CVSS 8.1), an unsafe. NET type instantiation in SharePoint\u2019s Business Connectivity Services.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The flaw, tracked as CVE-2026\u201355040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft\u2019s affected-product list covers only those three on-premises editions, and SharePoint Online is not among them. It lets a remote unauthenticated attacker assume a chosen user\u2019s identity. The attack has one prerequisite: the intruder has to [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[43,1492],"tags":[],"class_list":["post-242576","post","type-post","status-publish","format-standard","hentry","category-business","category-security"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242576","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=242576"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242576\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=242576"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=242576"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=242576"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}