CVE-2026-56155

Analyzed
Published: 14 Jul 2026, 17:05
Last modified:20 Aug 2026, 17:01

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
2.33% LOW
2% probability 0.00%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Jul 2026, 17:05
Published
Vulnerability first disclosed
14 Jul 2026, 00:00
Added to CISA KEV
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
28 Jul 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
20 Aug 2026, 17:01
Last Modified
Vulnerability information updated

Description

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 2.33% Percentile: 82%

Techniques & Countermeasures

  • CWE-1220Insufficient Granularity of Access Control

    The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

Affected Systems

  • microsoftwindows_10_1607

    < 10.0.14393.9339

  • microsoftwindows_10_1809

    < 10.0.17763.9020

  • microsoftwindows 10 version 1607

    ≥ 10.0.14393.0, < 10.0.14393.9339

  • microsoftwindows 10 version 1809

    ≥ 10.0.17763.0, < 10.0.17763.9020

  • microsoftwindows_server_2012

    na | r2 | ≥ 6.2.9200.0, < 6.2.9200.26226

  • microsoftwindows server 2012 r2

    ≥ 6.3.9600.0, < 6.3.9600.23291

  • microsoftwindows server 2012 r2 (server core installation)

    ≥ 6.3.9600.0, < 6.3.9600.23291

  • microsoftwindows server 2012 (server core installation)

    ≥ 6.2.9200.0, < 6.2.9200.26226

  • microsoftwindows_server_2016

    < 10.0.14393.9339 | ≥ 10.0.14393.0, < 10.0.14393.9339

  • microsoftwindows server 2016 (server core installation)

    ≥ 10.0.14393.0, < 10.0.14393.9339

  • microsoftwindows_server_2019

    < 10.0.17763.9020 | ≥ 10.0.17763.0, < 10.0.17763.9020

  • microsoftwindows server 2019 (server core installation)

    ≥ 10.0.17763.0, < 10.0.17763.9020

  • microsoftwindows_server_2022

    < 10.0.20348.5386 | ≥ 10.0.20348.0, < 10.0.20348.5386

  • microsoftwindows server 2025

    < 10.0.26100.33158 | ≥ 10.0.26100.0, < 10.0.26100.33158

  • microsoftwindows server 2025 (server core installation)

    ≥ 10.0.26100.0, < 10.0.26100.33158

References (2)