HIGH
CVE-2026-56155
CVSS
7.8
KEV
Description
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Summary dbcve.org
This vulnerability in Active Directory Federation Services (AD FS) stems from insufficient granularity of access control, allowing an authorized user to elevate their privileges locally on the affected system. The attacker already has some level of authorized access but can exploit the coarse access control mechanisms to gain higher-level privileges.
Mitigation
Apply Microsoft security updates for AD FS when available and review AD FS role assignments and access control policies to implement least-privilege principles. Conduct a thorough audit of existing AD FS user accounts and their permission levels.
Weakness (CWE)
CWE-1220
EPSS Score
0.35%
Probability of exploitation in next 30 days
28.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.