HIGH

CVE-2026-56155

Microsoft Windows 10 1607 2026-07-14 CVSS v3.1
CVSS
7.8
KEV

Description

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

Summary dbcve.org

This vulnerability in Active Directory Federation Services (AD FS) stems from insufficient granularity of access control, allowing an authorized user to elevate their privileges locally on the affected system. The attacker already has some level of authorized access but can exploit the coarse access control mechanisms to gain higher-level privileges.

Mitigation

Apply Microsoft security updates for AD FS when available and review AD FS role assignments and access control policies to implement least-privilege principles. Conduct a thorough audit of existing AD FS user accounts and their permission levels.

Weakness (CWE)

CWE-1220

EPSS Score

0.35%
Probability of exploitation in next 30 days
28.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE