# SharePoint JWT alg:none, impersonate any user

Source: https://startwithidentity.com/cves/cve-2023-29357/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

SharePoint Server verified [OAuth](https://startwithidentity.com/glossary/oauth/) [JWTs](https://startwithidentity.com/glossary/jwt/) in `ReadTokenCore()`. If the header set `alg` to `none`, signature verification was skipped. An unauthenticated attacker minted a token as Administrator. CVSS 9.8. Patched June 2023. STAR Labs chained it with CVE-2023-24955 at Pwn2Own for RCE. CISA added 29357 to KEV in January 2024 after exploitation.

## Why it matters

`alg:none` is a twenty-year-old JWT lesson showing up in a Microsoft product that many enterprises treat as an intranet [IdP](https://startwithidentity.com/glossary/identity-provider/). The same class returned in [SimpleHelp](https://startwithidentity.com/cves/cve-2026-48558/) and [WordPress OAuth SSO](https://startwithidentity.com/cves/cve-2025-9485/). If your JWT library lets the token pick the algorithm, you are on this list.

## What to do

- Patch on-prem SharePoint. If it was reachable after June 2023, review farm-admin and app-principal grants.
- Reject `alg:none` in every verifier you own. See the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).
- Do not expose SharePoint's OAuth endpoints to the internet.

## After you patch

Patching an authentication bypass stops new intrusions. It does not evict anyone already inside, and that is the step most teams skip.

- **Revoke every session and [refresh token](https://startwithidentity.com/glossary/refresh-token/)**, not just the passwords. A session issued before the patch is still valid after it.
- **Enumerate accounts created or modified during the exposure window**, including local accounts on the appliance itself, service accounts, and API tokens.
- **Remove authentication methods you did not add.** An attacker with administrative access enrols a factor so the access survives your remediation.
- **Rotate every credential the compromised system could reach**: directory service accounts used for user lookup, integration keys, and anything in its configuration store. See [secrets rotation](https://startwithidentity.com/glossary/secrets-rotation/).
- **Assume the device is a pivot, not a destination.** Check what it could authenticate to and treat that as in scope.

## Sources

- [NVD: CVE-2023-29357](https://nvd.nist.gov/vuln/detail/CVE-2023-29357)
- STAR Labs, SharePoint pre-auth RCE chain, September 2023
- CISA KEV
