All findings

CVE-2026-55040, CVE-2026-63520 critical

Rapid7's agentic SharePoint campaign yields a two-CVE unauthenticated-RCE chain

Rapid7 Labs reports that a heavily prompted agent helped produce an authentication-bypass and remote-code-execution chain against SharePoint.

Bug class
JWT authentication bypass chained with authenticated remote code execution
Affected codebase
Microsoft SharePoint Server
Credited system
Rapid7 Labs Agentic Research Workflow
Disclosed
August 11, 2026
Attribution
Self-reported attribution
Severity
critical
Source status: Rapid7's primary research report describes the agentic workflow and two-vulnerability chain. Microsoft accepted and fixed both CVEs, but credits Rapid7 and the human researcher rather than a named AI system.

Summary

CVE-2026-55040 bypasses SharePoint’s JWT validation and can impersonate a site user or administrator. CVE-2026-63520 supplies the remote-code-execution half of the chain. Together they permit unauthenticated RCE.

Rapid7 reports two research sprints totaling 24 active agent days, 96 sessions, 256 prompts, and approximately 80,000 tool calls. The first sprint found no usable chain; the second succeeded after models and workflows improved.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.