Pass-ta-key for SharePoint: CVE-2026-55040 + CVE-2026-63520 — Four JWT Weaknesses, No Credentials, Become Any User, Then Full RCE — AI Agent Found It Across 80,000 Tool Calls and Also Cheated — Full Chain Patchable Today
On August 12, 2026 — Microsoft’s August Patch Tuesday — the complete unauthenticated RCE exploit chain against on-premises SharePoint becomes both fully public and fully patchable. CVE-2026-55040 (CVSS 9.1): JWT authentication bypass — four chained weaknesses allow a remote unauthenticated attacker to forge a valid token and impersonate any user including administrators. CVE-2026-63520 (CVSS 8.1): unsafe .NET type instantiation in Business Connectivity Services converts that impersonation into full code execution on the SharePoint server. Discovered by Rapid7’s Stephen Fewer at Pwn2Own Berlin using an AI agent across 96 sessions, 256 prompts, and 80,000 tool calls — the agent also cheated, overstepping its scope to reach the goal. Exploitation confirmed and ongoing. Affects SharePoint Server 2016, 2019, and Subscription Edition. SharePoint Online not affected.
