Active Directory Threat: Public PoC Released for Certighost Domain-Takeover Flaw CVE-2026-54121

🛡️ Verified Threat IntelDigitalSpying Research Desk
📅 August 3, 2026⏱️ 6 min read

A functional public Proof-of-Concept (PoC) exploit targeting CVE-2026-54121—tracked in offensive security circles as "Certighost"—has been released across public threat-research channels. The vulnerability resides within Microsoft Active Directory Certificate Services (AD CS) enrollment endpoints, enabling any standard, unprivileged domain user account to escalate instantly to Enterprise Administrator via malicious Subject Alternative Name (SAN) validation lapses.

Root Cause Analysis: Flawed SAN Sanitization in AD CS

Active Directory Certificate Services serves as the core Public Key Infrastructure (PKI) backbone for Windows enterprise environments. In default configurations, certificate authorities evaluate incoming Certificate Signing Requests (CSRs) against predefined certificate templates. The vulnerability designated CVE-2026-54121 stems from an architectural intersection between enterprise CA configuration flags and cryptographic enrollment processing.

Specifically, the flaw activates when an Enterprise CA maintains the registry flag EDITF_ATTRIBUTESUBJECTALTNAME2 enabled, combined with a published template that permits client authentication (Enhanced Key Usage OID 1.3.6.1.5.5.7.3.2) or smart card logon (OID 1.3.6.1.4.1.311.20.2.2). Historically cataloged under the certified pre-owned escalation matrix as ESC6, Certighost introduces a distinct parsing bypass in the Active Directory Certificate Services Remote Protocol (MS-WCCE).

Under CVE-2026-54121, even when templates explicitly attempt to enforce CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH to derive identity strictly from Active Directory objects, an attacker can embed alternate identity extensions inside the cryptographic attributes segment of the request envelope. The internal CA parsing daemon prioritizes the unauthenticated user-supplied SAN over the authenticated RPC binding identity.

Critical Threat Advisory: ESC6 Mutation

Certighost bypasses earlier mitigations for ESC6 by encapsulating userPrincipalName (UPN) specifications inside fragmented ASN.1 attribute sequences that evade traditional string-matching checks while still resolving successfully during cryptographic signing by the CA.

Step-by-Step Anatomy of the Certighost Exploit Chain

Offensive security researchers and threat actor groups have demonstrated a four-stage execution chain that turns a non-privileged domain user session into unrestricted forest dominance:

  1. Target Identification and Template Enumeration: An adversary authenticated as a low-privileged domain user queries the Active Directory configuration naming context via LDAP to enumerate all published certificate templates. The attacker isolates templates permitting Domain Users enrollment permissions where client authentication EKUs are declared.
  2. Forged CSR Generation: Using specialized offensive tooling, the attacker drafts a PKCS#10 Certificate Signing Request. Within the request attributes, the attacker injects an alternate san:upn tag referencing the target Domain Controller computer account or the primary Domain Administrator account (e.g., Administrator@lab.internal).
  3. Certificate Issuance via MS-WCCE: The exploit script transmits the payload via RPC or HTTP Enrollment endpoints (CES/NDES). Due to the CVE-2026-54121 logic flaw, the Enterprise CA signs the certificate without validating whether the enrolling security principal owns the identity asserted in the SAN extension.
  4. PKINIT Kerberos Authentication: With the newly minted X.509 certificate and private key in hand, the attacker executes a Public Key Cryptography for Initial Authentication (PKINIT) exchange with the Kerberos Key Distribution Center (KDC). The KDC verifies the cryptographic signature against the Enterprise Root CA, extracts the administrative UPN, and returns an unconstrained Ticket Granting Ticket (TGT) along with the administrative NT hash.
# Certighost Exploitation Sequence via Public PoC
certipy req -u lowpriv@domain.local -p P@ssw0rd123! -ca CORP-CA -target ca.domain.local -template User -alt Administrator -dc-ip 10.0.0.1
certipy auth -pfx administrator.pfx -dc-ip 10.0.0.1
Attribute Exploitation Metric Operational Impact
Vulnerability Identifier CVE-2026-54121 (Certighost) Unauthenticated Identity Impersonation
CVSS v3.1 Score 8.8 (High) / Temporal 9.3 Complete Confidentiality, Integrity & Availability Loss
Attack Vector Network (AD CS RPC / MS-WCCE) Low Privilege User to Full Domain Controller TGT
Required Privileges Low (Standard Domain User) Zero User Interaction Required

Forensic Indicators and Detection Engineering

Threat detection teams and incident responders must immediately operationalize telemetry on all Active Directory Certificate Authority hosts and Domain Controllers. Detecting Certighost requires correlating certificate enrollment audit events with subsequent anomalous Kerberos authentications.

On the Enterprise CA servers, Windows Security Event ID 4886 (Certificate Services received a certificate request) and Event ID 4887 (Certificate Services approved a certificate request and issued a certificate) provide primary evidentiary records. Security teams must monitor these events for instances where the requester account name (SAMAccountName) does not match the Subject Alternative Name attributes embedded in the request attributes field.

On the Domain Controllers, Event ID 4768 (A Kerberos authentication ticket was requested) records the subsequent PKINIT logon. Pay close attention to logons where the Pre-Authentication Type indicates value 16 (PKINIT) or 17 (PKINIT draft), and verify that the client certificate serial number ties back to a verified, legitimately requested credential.

High-Fidelity Splunk Detection Logic

Search CA telemetry for EventCode=4887 where Attributes contains "san:upn=" or "subjectAltName" and Requester NOT LIKE "%$" AND Requester NOT LIKE "admin%". Cross-reference the issued serial number against EventCode=4768 CertificateSerialNumber within a 300-second window.

Defensive Remediation and Hardening Runbook

Addressing Certighost requires a disciplined, multi-layered hardening strategy to neutralize both the immediate vulnerability and the broader architectural risks of AD CS abuse:

  • Disable EDITF_ATTRIBUTESUBJECTALTNAME2: Ensure this dangerous CA flag is disabled across all Enterprise CAs. Run certutil -getreg policy\EditFlags to verify. If the bit is set, disable it immediately using certutil -setreg policy\EditFlags -EDITF_ATTRIBUTESUBJECTALTNAME2 followed by restarting the CertSvc service.
  • Deploy Security Updates: Apply Microsoft out-of-band security updates that enforce strict validation checks on certificate requests containing user-specified SAN attributes.
  • Enforce KB5014754 Strong Certificate Mapping: Enable full enforcement mode for Kerberos strong certificate mapping across all Domain Controllers. Strong mapping links certificates directly to target AD accounts using the security identifier (SID) extension (OID 1.3.6.1.4.1.311.25.2) embedded during issuance, rather than relying exclusively on mutable UPN strings.
  • Audit Published Certificate Templates: Execute automated auditing tools such as Certipy or PSPiaK to detect templates with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT enabled or enrollment agent constraints that lack manager approval workflows.
  • Enforce EPA on Enrollment Endpoints: Enable Extended Protection for Authentication (EPA) and require HTTPS with channel binding on Certificate Authority Web Enrollment (CAWE) and Network Device Enrollment Service (NDES) endpoints to eliminate NTLM relay amplification.
  • Restrict PKINIT Certificate Usage: Implement strict Issuance Policies and Object Identifiers within Kerberos PKINIT configurations to prevent arbitrary standard user certificates from qualifying for administrative logon tickets.

Continuous Certificate Telemetry and KQL Threat Hunting

To detect adversaries who may have already leveraged Certighost to plant persistent administrative certificates, enterprise hunting teams must inspect historical certificate database records and continuous Directory Services log streams. Using Microsoft Sentinel or Azure Log Analytics, threat hunters can deploy the following Kusto Query Language (KQL) query across unified security logs:

// KQL Query: Hunting Anomalous AD CS SAN Issuance & PKINIT Correlation
SecurityEvent
| where EventID == 4887
| extend ParsedAttributes = parse_json(EventData)
| extend Requester = tostring(ParsedAttributes.Requester),
         SubjectAltName = tostring(ParsedAttributes.SubjectAltName),
         CertSerialNumber = tostring(ParsedAttributes.SerialNumber)
| where SubjectAltName has_any ("admin", "da-", "svc-", "dc$")
| where not(Requester has_any ("admin", "da-", "svc-", "dc$"))
| project TimeGenerated, Computer, Requester, SubjectAltName, CertSerialNumber
| join kind=inner (
    SecurityEvent
    | where EventID == 4768
    | extend PKINIT_Cert = tostring(parse_json(EventData).CertSerialNumber)
    | where PreAuthType == 16
    | project LogonTime = TimeGenerated, TargetUserName, PKINIT_Cert, IpAddress
) on $left.CertSerialNumber == $right.PKINIT_Cert

By enforcing continuous posture management across all Active Directory Certificate Authorities and continuously reconciling certificate SAN attributes against Active Directory computer and user objects, security engineering teams can systematically neutralize Certighost exploitation before adversaries execute lateral movement or establish long-term persistence in the domain forest.

Classification:Cyber Security IntelligenceZero-Day AnalysisDefensive Engineering
🛡️

About the DigitalSpying Research Desk

The DigitalSpying Threat Intelligence Desk is composed of seasoned security researchers, reverse engineers, and blue team architects. Our mission is to publish reproducible, peer-audited threat analyses, hardware security evaluations, and defensive countermeasures.