Vulnerability record · CVE-2026-56155 · published 14 July 2026
CVE-2026-56155: Microsoft AD FS access control flaw allows local privilege elevation
Microsoft · Windows 10 1607
Active Directory Federation Services (AD FS) on multiple Windows client and server versions has insufficient granularity in its access control, letting an already-authorized local user perform actions beyond their intended privilege level. Because AD FS underpins federated authentication and token issuance, a privilege gain there can undermine trust decisions for the wider environment. The record gives no detail on the specific access-control check that fails or which versions are fixed.
Description
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high confidentiality, integrity and availability impact plus confirmed CISA KEV listing outweighs the low EPSS score.
What it is
Active Directory Federation Services (AD FS) on multiple Windows client and server versions has insufficient granularity in its access control, letting an already-authorized local user perform actions beyond their intended privilege level. Because AD FS underpins federated authentication and token issuance, a privilege gain there can undermine trust decisions for the wider environment. The record gives no detail on the specific access-control check that fails or which versions are fixed.
Impact
An attacker who already holds a low-privileged local account can elevate to a higher-privileged context on the AD FS host, gaining high confidentiality, integrity and availability impact per the CVSS vector. From that position they can potentially influence authentication and token issuance for federated services.
Attack surface
Reached locally (AV:L) with low privileges required (PR:L) and no user interaction (UI:N); the attacker must already have code execution or an interactive session on the AD FS system. It is not described as remotely reachable or unauthenticated.
Exploitation
CVE-2026-56155 was added to CISA KEV on 2026-07-14 with a remediation due date of 2026-07-28, indicating known exploitation in the wild. EPSS is low (0.00346, 28th percentile), and no ransomware campaign use is documented.
What to do
- Apply the Microsoft vendor update for AD FS on all listed Windows client and server versions as the first action.
- Follow CISA BOD 26-04 guidance, including the forensics triage requirements, and discontinue use of the product if mitigations are unavailable.
- Restrict and audit local logon rights on AD FS hosts so only necessary administrative accounts can obtain a session.
- Evaluate each AD FS host's internet exposure and prioritize patching of any externally reachable instances.
- Monitor AD FS and Windows security logs for unexpected privilege changes or token issuance by low-privileged accounts.
Detection
- Alert on local logon sessions on AD FS servers by accounts outside the approved administrative set.
- Monitor Windows security event logs for privilege escalation, token manipulation or new high-privilege group membership on AD FS hosts.
- Review AD FS token issuance and authentication logs for anomalies tied to low-privileged local accounts.
- Hunt for post-exploitation activity on AD FS servers, including new services, scheduled tasks or credential access attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-56155 to the Known Exploited Vulnerabilities catalog on 14 July 2026 as "Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability ". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 28 July 2026.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56155 | US Government Resource |
Track CVE-2026-56155 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-56155), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.