CVE-2026-52754
HIGHGhidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModule
Title source: cnaDescription
Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repository access controls, exfiltrate shared reverse engineering databases, and permanently compromise server integrity.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-5wxq-7qpv-65p2)
https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-5wxq-7qpv-65p2
Patch patch
Patch Commit (1)
https://github.com/NationalSecurityAgency/ghidra/commit/78729379e471bbb3d969409be6a8c3d24af84220
Patch patch
Patch Commit (2)
https://github.com/NationalSecurityAgency/ghidra/commit/79d8f164f8bb8b15cfb60c5d4faeb8e1c25d15ca
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/ghidra-authentication-bypass-via-null-signature-in-pkiauthenticationmodule
Scores
CVSS v3
8.8
EPSS
0.0025
EPSS Percentile
16.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-347
Status
published
Products (3)
nationalsecurityagency/ghidra
< 12.1
nationalsecurityagency/ghidra
12.1
nsa/ghidra
< 12.1
Published
Jun 10, 2026
Tracked Since
Jun 10, 2026