Security researchers have disclosed a critical exploit chain affecting on-premises Microsoft SharePoint Server that allows unauthenticated attackers to achieve remote code execution (RCE). The chain leverages two distinct vulnerabilities—an authentication bypass and an unsafe .NET type instantiation flaw—to provide full server control without valid credentials.

The vulnerability chain combines two CVEs to bypass security barriers:

  1. CVE-2026-55040 (Authentication Bypass): The first component targets SharePoint’s JSON Web Token (JWT) validation pipeline (SPJsonWebSecurityTokenHandlerV2). By exploiting weaknesses in this pipeline, an attacker can forge JWT tokens to impersonate privileged SharePoint users, effectively bypassing authentication requirements.
  2. CVE-2026-63520 (Unsafe .NET Type Instantiation): Once the attacker establishes a valid identity context, the second vulnerability provides the path to execution. CVE-2026-63520 exists within SharePoint’s Business Connectivity Services (BCS). Specifically, the DbTypeReflector.ResolveDotNetType()method fails to properly validate .NET types dynamically resolved from BDC model XML files.

By submitting a crafted BDC model, an attacker can force the server to instantiate arbitrary .NET types from the Global Assembly Cache (GAC). Using known gadget chain techniques—such as leveraging System.Windows.Data.ObjectDataProviderto invoke System.Diagnostics.Process.Start()—the attacker can execute arbitrary OS commands with the privileges of the SharePoint site’s service account.

This exploit chain was identified by Rapid7 Labs during a research project aimed at evaluating how AI-assisted agentic workflows, guided by subject matter experts, could accelerate vulnerability discovery and weaponization. The research required significant effort, involving approximately 120 hours of agent runtime and thousands of tool calls over several weeks. Researchers at VulnCheck dug into the exploit chain, as well.

"The auth bypass is enough to prove some impact, but not enough to demonstrate the criticality of the full chain or build complete protections. As a result, the VulnCheck research team developed a complete RCE exploit, along with a version scanner, Suricata and Snort rules, encrypted and unencrypted PCAPs, and ASM queries," Jonathan Peterson of VulnCheck wrote.

"SharePoint has a large deployment footprint and an appreciable internet-facing target population. ASM query engines show wildly differing counts of SharePoint servers on the open internet. After throwing out (copious) honeypots and de-duplicating, VulnCheck Target Intelligence finds at least 8,500 SharePoint servers online."

While the vulnerability itself is rated as a high risk, its ability to be chained with the authentication bypass creates a critical risk. The vulnerability affects all supported on-premises versions of SharePoint, including SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016.

SharePoint Online is not affected by this specific exploit chain.

Microsoft has released security updates to address these flaws across the impacted SharePoint versions. Organizations that might be affected should verify their build numbers and conduct thorough threat hunting to ensure no prior exploitation has occurred, as public proof-of-concept patterns for these vulnerabilities increase the likelihood of opportunistic attacks.