Certighost (CVE-2026-54121) — Impersonating a Domain Controller via AD CS

This article describes the exploitation of the vulnerability CVE-2026-54121. A low-privileged domain user can impersonate a domain controller by exploiting the fallback mechanism used when issuing certificates through AD CS. By supplying special request attributes — cdc (Client DC) and rmd (Remote Domain), the attacker forces the enterprise certification authority (CA) to connect to a host under their control over SMB and LDAP.
The CA then blindly trusts the directory objects it receives (objectSid and dNSHostName of the actual domain controller) and issues a certificate with the correct identity mapping. This allows the attacker to authenticate via PKINIT as the domain controller and effectively obtain its privileges.
Vulnerabilities
9.0
CVE-2026-54121
Products
Ad Cs
Certighost