CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
How it works
The weakness is categorized as CWE-1220, insufficient granularity of access control. In this class of flaw, permissions assigned to an authorized user or process are broader than required for the intended operation. An attacker who already possesses valid credentials or a session on the system can leverage the coarse access rules to perform actions that should be restricted, resulting in local privilege elevation.
Am I affected? How to find it in your systems
Microsoft Active Directory Federation Services runs on Windows Server systems configured for identity federation and authentication services. Inventory all servers that host the ADFS role or related federation components. Review installed server roles, service accounts, and configuration files to identify ADFS deployments. Check the specific versions and configurations in use against the vendor advisory, as the provided details do not list exact affected releases.
- Examine Windows event logs and ADFS-specific logs for unusual local authentication or authorization events that deviate from expected patterns.
- Confirm exposure by comparing your environment against the vendor advisory rather than relying on general indicators alone.
How to remediate
Apply the vendor update named in the advisory as the primary step. Follow all instructions provided by Microsoft for installing and verifying the fix on ADFS servers. After patching, review access control configurations for the affected component class to ensure permissions are limited to the minimum required for each role or operation.
If you can't patch immediately
Apply mitigations in accordance with vendor instructions while ensuring compliance with CISA BOD 26-04 guidance on prioritizing security updates. Segment ADFS servers from general-purpose networks to limit lateral movement opportunities. Monitor authentication and authorization activity for anomalies. Disable or restrict non-essential federation features if they are not required. Stakeholders must evaluate each asset's internet exposure and follow applicable BOD 26-04 requirements for cloud services or discontinue use if mitigations cannot be applied.
If your data may have been exposed
Actively exploited vulnerabilities of this type can contribute to unauthorized access and subsequent data exposure. You can run a free exposure scan of your email addresses to check against known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.