CVE-2026-52754

HIGH

Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModule

Title source: cna
STIX 2.1

Description

Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repository access controls, exfiltrate shared reverse engineering databases, and permanently compromise server integrity.

Scores

CVSS v3 8.8
EPSS 0.0025
EPSS Percentile 16.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (3)
nationalsecurityagency/ghidra < 12.1
nationalsecurityagency/ghidra 12.1
nsa/ghidra < 12.1
Published Jun 10, 2026
Tracked Since Jun 10, 2026