AI-Discovered Flaw Lets Attackers Break Into Microsoft SharePoint Without a Password
Security researchers have disclosed a serious vulnerability in Microsoft SharePoint that allows attackers to gain access as any user—including an administrator—without needing a valid account. Notably, much of the work behind discovering this exploit chain was carried out with the help of an AI agent, highlighting how artificial intelligence is increasingly being used to find complex security flaws.
The vulnerability, tracked as CVE-2026-55040, carries a severity score of 9.1 out of 10, making it a critical issue. It affects several widely used versions of SharePoint, including SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Because SharePoint is commonly used by businesses to store and share internal documents, a successful attack could give hackers unauthorised access to sensitive company data without needing to steal a password first.
While Microsoft's response and patch details were not fully outlined in the available report, the severity of this flaw means organisations running affected SharePoint versions should treat this as a high-priority issue. As AI tools make it easier for both defenders and attackers to identify vulnerabilities, businesses need to stay alert and ensure their systems are kept up to date.