Access Control Flaw in Active Directory Federation Services by Microsoft
CVE-2026-56155

7.8HIGH

Key Information:

Badges

📈 Score: 118👾 Exploit Exists🦅 CISA Reported

What is CVE-2026-56155?

CVE-2026-56155 is a security vulnerability identified in Microsoft’s Active Directory Federation Services (AD FS), a component widely used in enterprise environments to provide single sign-on and federated identity management capabilities. This specific vulnerability relates to an insufficient granularity of access control within AD FS, which allows an authorized attacker with access to potentially elevate their privileges locally. Such privilege escalation can lead to unauthorized access to sensitive data and critical infrastructure, compromising the integrity and confidentiality of organizational systems. The technical details suggest that, while the attacker may not be entirely outside the organization, their existing access can be exploited, making the issue particularly severe as it bypasses conventional perimeter defenses.

Potential impact of CVE-2026-56155

  1. Privilege Escalation: The primary impact of CVE-2026-56155 is that it enables attackers who already have some level of authorization to escalate their privileges. This can allow them to gain control over sensitive data and system functions that should be restricted, leading to potential data breaches and unauthorized actions within the system.

  2. Data Breaches and Information Theft: With elevated privileges, attackers can access sensitive databases and files, leading to the possibility of leaking confidential information. This can have severe implications for organizations, including loss of intellectual property and violation of data protection regulations.

  3. Increased Risk of Malware Infection: The vulnerability increases the likelihood of further exploitation. Once an attacker gains elevated privileges, they can install malware or additional exploits within the network, leading to broader system compromise, including the potential for ransomware deployment. The flexibility to maneuver within the network enhances the adversary’s capability to carry out extensive malicious activities.

CISA has reported CVE-2026-56155

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-56155 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9339

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.9020

Windows Server 2012 (Server Core installation) x64-based Systems 6.2.9200.0 < 6.2.9200.26226

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.