CVE-2026-56155
Vulnerability Summary
Timeline
Description
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 2.33%• Percentile: 82%
Techniques & Countermeasures
- CWE-1220•Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
Affected Systems
- microsoft•windows_10_1607
< 10.0.14393.9339
- microsoft•windows_10_1809
< 10.0.17763.9020
- microsoft•windows 10 version 1607
≥ 10.0.14393.0, < 10.0.14393.9339
- microsoft•windows 10 version 1809
≥ 10.0.17763.0, < 10.0.17763.9020
- microsoft•windows_server_2012
na | r2 | ≥ 6.2.9200.0, < 6.2.9200.26226
- microsoft•windows server 2012 r2
≥ 6.3.9600.0, < 6.3.9600.23291
- microsoft•windows server 2012 r2 (server core installation)
≥ 6.3.9600.0, < 6.3.9600.23291
- microsoft•windows server 2012 (server core installation)
≥ 6.2.9200.0, < 6.2.9200.26226
- microsoft•windows_server_2016
< 10.0.14393.9339 | ≥ 10.0.14393.0, < 10.0.14393.9339
- microsoft•windows server 2016 (server core installation)
≥ 10.0.14393.0, < 10.0.14393.9339
- microsoft•windows_server_2019
< 10.0.17763.9020 | ≥ 10.0.17763.0, < 10.0.17763.9020
- microsoft•windows server 2019 (server core installation)
≥ 10.0.17763.0, < 10.0.17763.9020
- microsoft•windows_server_2022
< 10.0.20348.5386 | ≥ 10.0.20348.0, < 10.0.20348.5386
- microsoft•windows server 2025
< 10.0.26100.33158 | ≥ 10.0.26100.0, < 10.0.26100.33158
- microsoft•windows server 2025 (server core installation)
≥ 10.0.26100.0, < 10.0.26100.33158