CVE-2026-54121: Certighost and the AD CS Flaw That Lets a Standard Account Impersonate a Domain Controller
How the CertiGhost AD CS vulnerability enables standard domain accounts to forge DC certificates and achieve instant domain takeover.
A critical Active Directory Certificate Services (AD CS) flaw nicknamed CertiGhost allows any standard domain user account to forge enterprise certificates and impersonate Domain Controllers with immediate forest-level compromise.
CVE-2026-54121 (AD CS Certificate Template Flaw)
Severity: Critical 9.8 (Domain Takeover)
Target: Active Directory Certificate Services (AD CS) PKI infrastructure
Impact: Instant Domain Admin privilege escalation from unprivileged domain accounts
How CertiGhost Works
CertiGhost exploits misconfigured certificate template enrollment permissions combined with SAN (Subject Alternative Name) spoofing, allowing unprivileged domain accounts to request Kerberos authentication certificates on behalf of the Domain Controller computer object.
Remediation
ENROLLEE_SUPPLIES_SUBJECT flags enabled.
Enforce strong certificate mapping via registry settings on Domain Controllers (KB5014754 enforcement mode).