Skip to content

Certighost: Vulnerability in Enterprise CAs Enables Privilege Escalation to Domain Controller

Bottom line: CVE-2026-54121 allows a standard domain user to gain domain controller privileges via a compromised enterprise CA, which is why PKI infrastructure must be secured as a Tier 0 identity component.

A vulnerability tracked as CVE-2026-54121 allows a standard domain user account to compromise an Enterprise Certificate Authority (CA) and thereby effectively obtain domain-controller-level privileges. The case once again demonstrates that PKI infrastructure must be treated as a Tier 0 identity component.

The vulnerability, dubbed “Certighost” (CVE-2026-54121), affects Enterprise Certificate Authorities in Active Directory environments. According to analysis by BleepingComputer, a regular domain user account is sufficient to ultimately obtain domain-controller-level privileges via the CA. The patch for the underlying flaw is described by the authors as comparatively straightforward — however, the real challenge lies in the structural root cause: standing privileges and implicit trust within the PKI architecture.

This report is relevant for CISOs because Certificate Authorities in many organizations are not secured with the same rigor as domain controllers themselves, even though they technically hold the same level of trust. A compromised CA allows attackers to issue arbitrary certificates, impersonate privileged accounts, and establish a persistent, hard-to-detect foothold in the domain. Compromising an Enterprise CA is therefore effectively equivalent to compromising the entire domain.

The article places the case within a broader issue that has been known since the earliest ADCS attack techniques (ESC1 through ESC8 and subsequent variants): misconfigurations and overly permissive access rights on CA templates and CA servers themselves open up attack paths that go beyond classic patch management. The core recommendation is therefore to formally classify PKI infrastructure as a Tier 0 asset, with correspondingly restricted administrative access, just-in-time privilege assignment instead of standing permissions, and regular audits of CA templates and access rights.

For practical implementation, in addition to promptly applying the available patch, it is recommended to review all Enterprise CA configurations for known ADCS vulnerability patterns, reduce standing administrator rights on CA servers, and integrate the PKI into regular Tier 0 monitoring, as is already standard practice for domain controllers.


Source: www.bleepingcomputer.com · Published August 17, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: