CVSS
7.8
CVSS v3.1
EPSS
2.3%
Exploit Prediction Score
Published
July 14, 2026
Exploitability
Exploited in the wild (CISA KEV)
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).