PT-2026-58259 · Microsoft · Active Directory Federation Services+1

CVE-2026-56155

·

Published

2026-07-14

·

Updated

2026-07-27

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Active Directory Federation Services (affected versions not specified)
Description An access control weakness exists in the service and admin surfaces of Microsoft Active Directory Federation Services (AD FS) due to insufficient granularity in authorization checks. This improper design allows overly broad permissions to be applied or enforced. An authorized attacker with local access can abuse these permissive controls to perform actions beyond their intended role, leading to privilege escalation. Successful exploitation can compromise AD FS operations and downstream identity trust, impacting the confidentiality, integrity, and availability of federated authentication flows.
Recommendations Apply the latest cumulative updates immediately.

Fix

DoS

RCE

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09722
CVE-2026-56155

Affected Products

Active Directory Federation Services
Windows