CVE-2026-54121
HIGHMicrosoft Windows 10 Version 1607 - Active Directory Certificate Services Elevation of Privilege Vulnerability
Title source: ruleExploitation Summary
EIP tracks 7 public exploits for CVE-2026-54121. PoCs published by aniqfakhrul, ChPratik, marcgoam.
AI-analyzed exploit summary This PoC exploits CVE-2026-54121 (Certighost), a certificate-based authentication bypass in Active Directory Certificate Services (AD CS). The exploit creates a rogue computer account, then uses malicious LDAP/SMB listeners to trick a Certificate Authority (CA) into issuing a certificate impersonating a domain controller, enabling Kerberos authentication as the DC.
Description
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
Exploits (7)
This PoC exploits CVE-2026-54121 (Certighost), a certificate-based authentication bypass in Active Directory Certificate Services (AD CS). The exploit creates a rogue computer account, then uses malicious LDAP/SMB listeners to trick a Certificate Authority (CA) into issuing a certificate impersonating a domain controller, enabling Kerberos authentication as the DC.
This repository provides an in-depth technical analysis of CVE-2026-54121 (Certighost), an Active Directory Certificate Services (AD CS) elevation-of-privilege vulnerability caused by improper authorization in the certificate enrollment chase fallback path. The report includes root cause analysis, patch details, attack prerequisites, detection guidance, and defensive recommendations, but does not contain exploit code.
This PoC exploits CVE-2026-54121 (CertiGhost), a certificate misissuance vulnerability in Active Directory Certificate Services (AD CS). It manipulates the CA's authentication process via rogue LSA/LDAP servers to issue a valid certificate for a domain controller, impersonating a computer account, enabling Kerberos authentication (PKINIT) as the DC.
This repository contains a detailed technical writeup of CVE-2026-54121, a vulnerability in Active Directory Certificate Services (AD CS) where a requester-controlled chase target allows a low-privileged user to obtain a Domain Controller certificate. The analysis includes root cause, exploit chain, and validation path details.
This exploit targets CVE-2026-54121, a vulnerability in Active Directory Certificate Services (AD CS) enabling domain privilege escalation via crafted certificate requests. The PoC implements a full attack chain including LDAP queries, NTLM authentication, and Kerberos ticket manipulation to compromise domain credentials.
The repository contains no actual exploit code, technical details, or vulnerability analysis for CVE-2026-54121. It only includes a README with donation requests, setup instructions, and legal disclaimers, alongside a generic license file.
The repository contains only a README.md file with the CVE identifier and no technical details, exploit code, or vulnerability analysis. It serves as a placeholder with minimal content.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H