Knox CVE Database
/
CVE-2026-56155
High
7.8

CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

Added to the CISA KEV catalog:
July 14, 2026

Overview

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

Vulnerability details

Affected vendor
Microsoft
Affected product
Active Directory Federation Services
Weakness type (CWE)
CWE-1220

CWE-1220 (Insufficient Granularity of Access Control) describes a system that implements access checks but at a resolution too coarse to separate distinct privilege levels that should be kept apart. In AD FS, the federation service runs privileged operations, management interfaces, and configuration stores (relying party trusts, claims rules, token-signing certificate material) that are meant to be reachable only by AD FS administrators. When the underlying access control model fails to distinguish an ordinary authenticated local user or service context from an AD FS administrative context, a boundary that should exist at a fine-grained level collapses into an all-or-nothing check.

The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates an attacker who already holds low-privilege, authenticated local access to the AD FS server can exploit the coarse authorization check without further complexity or user interaction to reach complete confidentiality, integrity, and availability impact. In practice this means a local low-privilege account or compromised service could escalate to the privilege level of the AD FS service account or SYSTEM, gaining the ability to alter federation trust configuration, access token-signing key material, or otherwise assume full control of the federation server — a high-value pivot point given AD FS's role in issuing authentication tokens across trusted relying parties.

Severity and impact

7.8
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review AD FS Admin and Debug event logs for configuration changes to relying party trusts, claims rules, or certificates initiated by non-administrative accounts.
  • Monitor Windows Security event log for local logon events (4624/4672) and process creation (4688) on AD FS servers showing privilege elevation from standard to SYSTEM or service-account context.
  • Audit execution of AD FS PowerShell management cmdlets (e.g., Set-/Get-AdfsRelyingPartyTrust, Set-AdfsProperties) and flag invocations by accounts outside the designated AD FS admin group.
  • Track changes to ACLs on the AD FS configuration database, WID/SQL store, and certificate store for unexpected modifications outside change windows.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 28, 2026

Additional hardening

  • Restrict interactive and remote local logon on AD FS servers to a minimal, tightly controlled administrative group; remove standing access for standard user or service accounts.
  • Place AD FS servers in a dedicated tier-0/high-privilege management tier with no lateral trust from lower-tier systems, consistent with standard AD administrative tiering models.
  • Require AD FS administration to occur only from privileged access workstations (PAWs) rather than general-purpose endpoints, reducing exposure to locally compromised sessions.
  • Periodically audit and minimize the set of local accounts and service identities present on AD FS servers, removing any that do not require server-local access.

Key dates

Published (NVD)
July 14, 2026
Added to CISA KEV
July 14, 2026
Remediation deadline
July 28, 2026
Last updated
July 15, 2026

References

Frequently asked questions

Does CVE-2026-56155 affect my FedRAMP authorization?

If Microsoft Active Directory Federation Services runs inside your authorization boundary, yes. CVE-2026-56155 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of July 28, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-56155?

Knox doesn't patch your software for you — remediating Microsoft Active Directory Federation Services is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2026-56155 isn't remediated by July 28, 2026?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting