
CVE-2026-54121
CertiGhost
CVE-2026-54121 ("Certighost") is a high-severity privilege escalation vulnerability affecting Microsoft Active Directory Certificate Services (AD CS).
The vulnerability allows an authenticated domain user to abuse certificate enrollment behavior and obtain a certificate capable of impersonating a Domain Controller, potentially leading to full Active Directory compromise.
⚠️ This repository is intended only for authorized security research, detection engineering, and defensive testing.
Successful exploitation may allow an attacker to:
Authenticated User
│
▼
AD CS Certificate Enrollment
│
▼
Authorization Bypass
│
▼
Issue DC Certificate
│
▼
PKINIT Authentication
│
▼
DCSync
│
▼
Full Active Directory Compromise
Monitor for:
CVE-2026-54121/
│
├── README.md
├── LICENSE
├── banner.png
├── docs/
│ ├── advisory.md
│ ├── detection.md
│ └── mitigation.md
├── iocs/
│ └── indicators.md
└── images/
This repository is provided for educational, defensive, and authorized security research purposes only.
The maintainers are not responsible for misuse or unauthorized activities performed using the information contained herein.
Made with ❤️ by the Security Research Community
| Item | Value |
|---|
| CVE | CVE-2026-54121 |
| Codename | Certighost |
| Severity | High |
| CVSS | 8.8 |
| Attack Vector | Network |
| Privileges Required | Low |
| User Interaction | None |
| Scope | Changed |
| Impact | Domain Compromise |