Source status: Rapid7's primary research report describes the agentic workflow and two-vulnerability chain. Microsoft accepted and fixed both CVEs, but credits Rapid7 and the human researcher rather than a named AI system.
Summary
CVE-2026-55040 bypasses SharePoint’s JWT validation and can impersonate a site user or administrator. CVE-2026-63520 supplies the remote-code-execution half of the chain. Together they permit unauthenticated RCE.
Rapid7 reports two research sprints totaling 24 active agent days, 96 sessions, 256 prompts, and approximately 80,000 tool calls. The first sprint found no usable chain; the second succeeded after models and workflows improved.
References
- Rapid7: SharePoint JWT bypass and RCE chain
- Microsoft: CVE-2026-55040
- Microsoft: CVE-2026-63520
- Microsoft SharePoint August hotfix
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.