Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Active Directory Federation Services (AD FS) on affected Windows Server versions contains an insufficient granularity of access control flaw (CWE-1220). AD FS exposes administrative operations and configuration interfaces that should be restricted to privileged accounts. When access controls are defined at too coarse a level, the boundary between what a low-privileged local user can invoke and what requires administrative rights collapses, allowing operations that carry elevated impact to be reached without the corresponding privilege check. This class of flaw differs from a missing access control entirely: controls exist, but they do not discriminate finely enough between principals.
An attacker who holds an existing low-privileged, authorized local account on a Windows Server running AD FS can invoke AD FS functionality or modify AD FS configuration that should be restricted to administrators. The specific operation or interface path is not disclosed in available sources. Successful exploitation produces high confidentiality, integrity, and availability impact on the local system. Because the attacker must already have local authenticated access and AD FS must be installed and running, the attack surface is limited to systems where AD FS is deployed and where the attacker has obtained at minimum a low-privileged local account.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Microsoft Active Directory Federation Services runs inside your authorization boundary, CVE-2026-56155 is your problem. CISA has listed it in the Known Exploited Vulnerabilities catalog with a remediation deadline of July 28, 2026. For a FedRAMP-authorized service, an unpatched KEV inside the boundary is a finding: one you either remediate or formally document a mitigation for before your assessor or sponsoring agency raises it first.
Remediating Microsoft Active Directory Federation Services is your responsibility under the FedRAMP shared-responsibility model. Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; maintaining a defensible compliance posture while you do it is not something you handle alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-56155 surfaces, exposure is identified through ongoing monitoring rather than surfacing only when an assessor flags it at review time.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If you miss the July 28, 2026 deadline, CVE-2026-56155 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a hard conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









