Certighost (CVE-2026-54121): How Low-Privilege Users Impersonate Domain Controllers
Introduction Active Directory Certificate Services (AD CS) serves as a foundational component in modern enterprise identity environments, facilitating public key infrastructure (PKI), machine authentication, VPN access, and smart card logins. However, misconfigurations and deep-seated flaws in how Enterprise Certificate Authorities (CAs) process incoming certificate requests or resolve directory objects can create severe privilege escalation vectors. The Certighost vulnerability (CVE-2026-54121) exposes a critical breakdown in this identity trust boundary, allowing an