Access Control Flaw in Active Directory Federation Services by Microsoft
CVE-2026-56155
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 14 July 2026
Badges
What is CVE-2026-56155?
CVE-2026-56155 is a security vulnerability identified in Microsoft’s Active Directory Federation Services (AD FS), a component widely used in enterprise environments to provide single sign-on and federated identity management capabilities. This specific vulnerability relates to an insufficient granularity of access control within AD FS, which allows an authorized attacker with access to potentially elevate their privileges locally. Such privilege escalation can lead to unauthorized access to sensitive data and critical infrastructure, compromising the integrity and confidentiality of organizational systems. The technical details suggest that, while the attacker may not be entirely outside the organization, their existing access can be exploited, making the issue particularly severe as it bypasses conventional perimeter defenses.
Potential impact of CVE-2026-56155
-
Privilege Escalation: The primary impact of CVE-2026-56155 is that it enables attackers who already have some level of authorization to escalate their privileges. This can allow them to gain control over sensitive data and system functions that should be restricted, leading to potential data breaches and unauthorized actions within the system.
-
Data Breaches and Information Theft: With elevated privileges, attackers can access sensitive databases and files, leading to the possibility of leaking confidential information. This can have severe implications for organizations, including loss of intellectual property and violation of data protection regulations.
-
Increased Risk of Malware Infection: The vulnerability increases the likelihood of further exploitation. Once an attacker gains elevated privileges, they can install malware or additional exploits within the network, leading to broader system compromise, including the potential for ransomware deployment. The flexibility to maneuver within the network enhances the adversary’s capability to carry out extensive malicious activities.
CISA has reported CVE-2026-56155
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-56155 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9339
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.9020
Windows Server 2012 (Server Core installation) x64-based Systems 6.2.9200.0 < 6.2.9200.26226