← Vulnerability feed

Vulnerability record · CVE-2026-56155 · published 14 July 2026

CVE-2026-56155: Microsoft AD FS access control flaw allows local privilege elevation

Microsoft · Windows 10 1607

Active Directory Federation Services (AD FS) on multiple Windows client and server versions has insufficient granularity in its access control, letting an already-authorized local user perform actions beyond their intended privilege level. Because AD FS underpins federated authentication and token issuance, a privilege gain there can undermine trust decisions for the wider environment. The record gives no detail on the specific access-control check that fails or which versions are fixed.

7.8 CVSS 3.1 High CISA KEV since 14 Jul 2026 EPSS 0.35% · top 74.4% CWE-1220 · CWE-1220
7.8CVSS 3.1 base score
0.35%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
2References
15 Jul 2026Last modified by NVD

Description

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityCVSS 7.8 with high confidentiality, integrity and availability impact plus confirmed CISA KEV listing outweighs the low EPSS score.

What it is

Active Directory Federation Services (AD FS) on multiple Windows client and server versions has insufficient granularity in its access control, letting an already-authorized local user perform actions beyond their intended privilege level. Because AD FS underpins federated authentication and token issuance, a privilege gain there can undermine trust decisions for the wider environment. The record gives no detail on the specific access-control check that fails or which versions are fixed.

Impact

An attacker who already holds a low-privileged local account can elevate to a higher-privileged context on the AD FS host, gaining high confidentiality, integrity and availability impact per the CVSS vector. From that position they can potentially influence authentication and token issuance for federated services.

Attack surface

Reached locally (AV:L) with low privileges required (PR:L) and no user interaction (UI:N); the attacker must already have code execution or an interactive session on the AD FS system. It is not described as remotely reachable or unauthenticated.

Exploitation

CVE-2026-56155 was added to CISA KEV on 2026-07-14 with a remediation due date of 2026-07-28, indicating known exploitation in the wild. EPSS is low (0.00346, 28th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the Microsoft vendor update for AD FS on all listed Windows client and server versions as the first action.
  • Follow CISA BOD 26-04 guidance, including the forensics triage requirements, and discontinue use of the product if mitigations are unavailable.
  • Restrict and audit local logon rights on AD FS hosts so only necessary administrative accounts can obtain a session.
  • Evaluate each AD FS host's internet exposure and prioritize patching of any externally reachable instances.
  • Monitor AD FS and Windows security logs for unexpected privilege changes or token issuance by low-privileged accounts.

Detection

  • Alert on local logon sessions on AD FS servers by accounts outside the approved administrative set.
  • Monitor Windows security event logs for privilege escalation, token manipulation or new high-privilege group membership on AD FS hosts.
  • Review AD FS token issuance and authentication logs for anomalies tied to low-privileged local accounts.
  • Hunt for post-exploitation activity on AD FS servers, including new services, scheduled tasks or credential access attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-56155 to the Known Exploited Vulnerabilities catalog on 14 July 2026 as "Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability ". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 28 July 2026.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-56155 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-1350Windows DNS Server improper input validation remote code executionWindows DNS servers fail to properly handle certain requests, allowing remote code execution. The flaw is network-reachable, needs no authentication …KEVEPSS 97%analysed9.8CVE-2026-33824Double free in Windows IKE Extension enables remote code executionA double free flaw (CWE-415) exists in the Windows IKE Extension, reachable over the network by an unauthenticated attacker. Successful exploitation …KEVEPSS 1.6%analysed9.8CVE-2025-59287Microsoft WSUS deserialization flaw allows unauthenticated remote code executionWindows Server Update Service (WSUS) deserializes untrusted data, letting an unauthenticated network attacker run code on the server. The flaw is rat…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed9.0CVE-2020-1040Microsoft Hyper-V RemoteFX vGPU input validation remote code executionHyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, allowing remote code …KEVEPSS 7.4%analysed8.8CVE-2026-21510Windows Shell protection mechanism failure allows security feature bypassWindows Shell contains a protection mechanism failure (CWE-693) that lets an unauthorized attacker bypass a security feature over a network. The flaw…KEVEPSS 24%analysed8.8CVE-2026-21513Microsoft MSHTML security feature bypass on WindowsCVE-2026-21513 is a protection mechanism failure (CWE-693) in the Microsoft MSHTML Framework that lets an unauthorized attacker bypass a security fea…KEVEPSS 16%analysed

Source: NIST National Vulnerability Database (record CVE-2026-56155), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.