Knox CVE Database
/
CVE-2026-56155
High
7.8

CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

Added to the CISA KEV catalog:
July 14, 2026

Overview

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

Vulnerability details

Affected vendor
Microsoft
Affected product
Active Directory Federation Services
Weakness type (CWE)
CWE-1220

Active Directory Federation Services (AD FS) on affected Windows Server versions contains an insufficient granularity of access control flaw (CWE-1220). AD FS exposes administrative operations and configuration interfaces that should be restricted to privileged accounts. When access controls are defined at too coarse a level, the boundary between what a low-privileged local user can invoke and what requires administrative rights collapses, allowing operations that carry elevated impact to be reached without the corresponding privilege check. This class of flaw differs from a missing access control entirely: controls exist, but they do not discriminate finely enough between principals.


An attacker who holds an existing low-privileged, authorized local account on a Windows Server running AD FS can invoke AD FS functionality or modify AD FS configuration that should be restricted to administrators. The specific operation or interface path is not disclosed in available sources. Successful exploitation produces high confidentiality, integrity, and availability impact on the local system. Because the attacker must already have local authenticated access and AD FS must be installed and running, the attack surface is limited to systems where AD FS is deployed and where the attacker has obtained at minimum a low-privileged local account.

Severity and impact

7.8
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review Windows Security event logs on AD FS servers for privilege-use events (Event IDs 4672, 4673) associated with accounts that are not members of AD FS administrator or Domain Admins groups, particularly where AD FS service or configuration operations follow.
  • Audit AD FS Admin event log (Applications and Services Logs > AD FS > Admin) for configuration-change entries originating from non-administrative accounts; any such entry on an unpatched server warrants immediate investigation.
  • Monitor local account activity on AD FS servers for interactive or service logons by accounts outside the expected administrative set, especially where subsequent process activity involves AD FS service binaries or configuration paths.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 28, 2026

Additional hardening

  • Restrict local logon rights on AD FS servers to the minimum required administrative accounts using Group Policy (User Rights Assignment: Allow log on locally, Deny log on locally).
  • Place AD FS servers behind network controls that prevent general user workstations from establishing local sessions; treat AD FS infrastructure as Tier 0 and enforce jump-host access patterns.
  • Audit and remove unnecessary local accounts on AD FS servers; apply the principle of least privilege so that no non-administrative user holds a local account on federation infrastructure.
  • Where patching cannot be applied immediately, consider temporarily disabling non-essential local user accounts on AD FS servers and increasing audit logging verbosity on AD FS Admin and Security event channels.

Key dates

Published (NVD)
July 14, 2026
Added to CISA KEV
July 14, 2026
Remediation deadline
July 28, 2026
Last updated
July 15, 2026

References

Frequently asked questions

Does CVE-2026-56155 affect my FedRAMP authorization?

If Microsoft Active Directory Federation Services runs inside your authorization boundary, CVE-2026-56155 is your problem. CISA has listed it in the Known Exploited Vulnerabilities catalog with a remediation deadline of July 28, 2026. For a FedRAMP-authorized service, an unpatched KEV inside the boundary is a finding: one you either remediate or formally document a mitigation for before your assessor or sponsoring agency raises it first.

How does Knox help me handle CVE-2026-56155?

Remediating Microsoft Active Directory Federation Services is your responsibility under the FedRAMP shared-responsibility model. Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; maintaining a defensible compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-56155 surfaces, exposure is identified through ongoing monitoring rather than surfacing only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-56155 isn't remediated by July 28, 2026?

If you miss the July 28, 2026 deadline, CVE-2026-56155 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a hard conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting