Alleged Microsoft SharePoint JWT token authentication bypass vulnerability
- 事件类型
- Vulnerability
- 报告时间
- 2026-08-12 10:48:10
- 被攻击国家/地区
- USA
- 被攻击行业
- Information Technology (IT) Services
- 被攻击组织
- microsoft
- 被攻击域名
- microsoft.com
- 攻击组织
- Scattered Spider
- 信息来源
- telegram
Original Text
查看原文
原文内容
The group claims to have identified a Microsoft SharePoint authentication bypass vulnerability that allegedly allows remote unauthenticated attackers to bypass authentication and perform operations as a SharePoint site user or administrator. The vulnerability reportedly involves issues in the JWT token validation process.
原图