A functional public Proof-of-Concept (PoC) exploit targeting CVE-2026-54121—tracked in offensive security circles as "Certighost"—has been released across public threat-research channels. The vulnerability resides within Microsoft Active Directory Certificate Services (AD CS) enrollment endpoints, enabling any standard, unprivileged domain user account to escalate instantly to Enterprise Administrator via malicious Subject Alternative Name (SAN) validation lapses.
Root Cause Analysis: Flawed SAN Sanitization in AD CS
Active Directory Certificate Services serves as the core Public Key Infrastructure (PKI) backbone for Windows enterprise environments. In default configurations, certificate authorities evaluate incoming Certificate Signing Requests (CSRs) against predefined certificate templates. The vulnerability designated CVE-2026-54121 stems from an architectural intersection between enterprise CA configuration flags and cryptographic enrollment processing.
Specifically, the flaw activates when an Enterprise CA maintains the registry flag EDITF_ATTRIBUTESUBJECTALTNAME2 enabled, combined with a published template that permits client authentication (Enhanced Key Usage OID 1.3.6.1.5.5.7.3.2) or smart card logon (OID 1.3.6.1.4.1.311.20.2.2). Historically cataloged under the certified pre-owned escalation matrix as ESC6, Certighost introduces a distinct parsing bypass in the Active Directory Certificate Services Remote Protocol (MS-WCCE).
Under CVE-2026-54121, even when templates explicitly attempt to enforce CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH to derive identity strictly from Active Directory objects, an attacker can embed alternate identity extensions inside the cryptographic attributes segment of the request envelope. The internal CA parsing daemon prioritizes the unauthenticated user-supplied SAN over the authenticated RPC binding identity.
Certighost bypasses earlier mitigations for ESC6 by encapsulating userPrincipalName (UPN) specifications inside fragmented ASN.1 attribute sequences that evade traditional string-matching checks while still resolving successfully during cryptographic signing by the CA.
Step-by-Step Anatomy of the Certighost Exploit Chain
Offensive security researchers and threat actor groups have demonstrated a four-stage execution chain that turns a non-privileged domain user session into unrestricted forest dominance:
- Target Identification and Template Enumeration: An adversary authenticated as a low-privileged domain user queries the Active Directory configuration naming context via LDAP to enumerate all published certificate templates. The attacker isolates templates permitting Domain Users enrollment permissions where client authentication EKUs are declared.
- Forged CSR Generation: Using specialized offensive tooling, the attacker drafts a PKCS#10 Certificate Signing Request. Within the request attributes, the attacker injects an alternate
san:upntag referencing the target Domain Controller computer account or the primary Domain Administrator account (e.g.,Administrator@lab.internal). - Certificate Issuance via MS-WCCE: The exploit script transmits the payload via RPC or HTTP Enrollment endpoints (CES/NDES). Due to the CVE-2026-54121 logic flaw, the Enterprise CA signs the certificate without validating whether the enrolling security principal owns the identity asserted in the SAN extension.
- PKINIT Kerberos Authentication: With the newly minted X.509 certificate and private key in hand, the attacker executes a Public Key Cryptography for Initial Authentication (PKINIT) exchange with the Kerberos Key Distribution Center (KDC). The KDC verifies the cryptographic signature against the Enterprise Root CA, extracts the administrative UPN, and returns an unconstrained Ticket Granting Ticket (TGT) along with the administrative NT hash.
# Certighost Exploitation Sequence via Public PoC
certipy req -u lowpriv@domain.local -p P@ssw0rd123! -ca CORP-CA -target ca.domain.local -template User -alt Administrator -dc-ip 10.0.0.1
certipy auth -pfx administrator.pfx -dc-ip 10.0.0.1
| Attribute | Exploitation Metric | Operational Impact |
|---|---|---|
| Vulnerability Identifier | CVE-2026-54121 (Certighost) | Unauthenticated Identity Impersonation |
| CVSS v3.1 Score | 8.8 (High) / Temporal 9.3 | Complete Confidentiality, Integrity & Availability Loss |
| Attack Vector | Network (AD CS RPC / MS-WCCE) | Low Privilege User to Full Domain Controller TGT |
| Required Privileges | Low (Standard Domain User) | Zero User Interaction Required |
Forensic Indicators and Detection Engineering
Threat detection teams and incident responders must immediately operationalize telemetry on all Active Directory Certificate Authority hosts and Domain Controllers. Detecting Certighost requires correlating certificate enrollment audit events with subsequent anomalous Kerberos authentications.
On the Enterprise CA servers, Windows Security Event ID 4886 (Certificate Services received a certificate request) and Event ID 4887 (Certificate Services approved a certificate request and issued a certificate) provide primary evidentiary records. Security teams must monitor these events for instances where the requester account name (SAMAccountName) does not match the Subject Alternative Name attributes embedded in the request attributes field.
On the Domain Controllers, Event ID 4768 (A Kerberos authentication ticket was requested) records the subsequent PKINIT logon. Pay close attention to logons where the Pre-Authentication Type indicates value 16 (PKINIT) or 17 (PKINIT draft), and verify that the client certificate serial number ties back to a verified, legitimately requested credential.
Search CA telemetry for EventCode=4887 where Attributes contains "san:upn=" or "subjectAltName" and Requester NOT LIKE "%$" AND Requester NOT LIKE "admin%". Cross-reference the issued serial number against EventCode=4768 CertificateSerialNumber within a 300-second window.
Defensive Remediation and Hardening Runbook
Addressing Certighost requires a disciplined, multi-layered hardening strategy to neutralize both the immediate vulnerability and the broader architectural risks of AD CS abuse:
- Disable EDITF_ATTRIBUTESUBJECTALTNAME2: Ensure this dangerous CA flag is disabled across all Enterprise CAs. Run
certutil -getreg policy\EditFlagsto verify. If the bit is set, disable it immediately usingcertutil -setreg policy\EditFlags -EDITF_ATTRIBUTESUBJECTALTNAME2followed by restarting theCertSvcservice. - Deploy Security Updates: Apply Microsoft out-of-band security updates that enforce strict validation checks on certificate requests containing user-specified SAN attributes.
- Enforce KB5014754 Strong Certificate Mapping: Enable full enforcement mode for Kerberos strong certificate mapping across all Domain Controllers. Strong mapping links certificates directly to target AD accounts using the security identifier (SID) extension (OID
1.3.6.1.4.1.311.25.2) embedded during issuance, rather than relying exclusively on mutable UPN strings. - Audit Published Certificate Templates: Execute automated auditing tools such as Certipy or PSPiaK to detect templates with
CT_FLAG_ENROLLEE_SUPPLIES_SUBJECTenabled or enrollment agent constraints that lack manager approval workflows. - Enforce EPA on Enrollment Endpoints: Enable Extended Protection for Authentication (EPA) and require HTTPS with channel binding on Certificate Authority Web Enrollment (CAWE) and Network Device Enrollment Service (NDES) endpoints to eliminate NTLM relay amplification.
- Restrict PKINIT Certificate Usage: Implement strict Issuance Policies and Object Identifiers within Kerberos PKINIT configurations to prevent arbitrary standard user certificates from qualifying for administrative logon tickets.
Continuous Certificate Telemetry and KQL Threat Hunting
To detect adversaries who may have already leveraged Certighost to plant persistent administrative certificates, enterprise hunting teams must inspect historical certificate database records and continuous Directory Services log streams. Using Microsoft Sentinel or Azure Log Analytics, threat hunters can deploy the following Kusto Query Language (KQL) query across unified security logs:
// KQL Query: Hunting Anomalous AD CS SAN Issuance & PKINIT Correlation
SecurityEvent
| where EventID == 4887
| extend ParsedAttributes = parse_json(EventData)
| extend Requester = tostring(ParsedAttributes.Requester),
SubjectAltName = tostring(ParsedAttributes.SubjectAltName),
CertSerialNumber = tostring(ParsedAttributes.SerialNumber)
| where SubjectAltName has_any ("admin", "da-", "svc-", "dc$")
| where not(Requester has_any ("admin", "da-", "svc-", "dc$"))
| project TimeGenerated, Computer, Requester, SubjectAltName, CertSerialNumber
| join kind=inner (
SecurityEvent
| where EventID == 4768
| extend PKINIT_Cert = tostring(parse_json(EventData).CertSerialNumber)
| where PreAuthType == 16
| project LogonTime = TimeGenerated, TargetUserName, PKINIT_Cert, IpAddress
) on $left.CertSerialNumber == $right.PKINIT_Cert
By enforcing continuous posture management across all Active Directory Certificate Authorities and continuously reconciling certificate SAN attributes against Active Directory computer and user objects, security engineering teams can systematically neutralize Certighost exploitation before adversaries execute lateral movement or establish long-term persistence in the domain forest.