Overview
What is CVE-2026-56155?
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
CISA lists CVE-2026-56155 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Microsoft Active Directory Federation Services.
Public exploit: Not collected. Review the linked vendor advisory and apply the mitigation or fixed release for your affected product.
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.