<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/certighost-cve-2026-54121--axfow8dnw" -->

---
title: Certighost (CVE-2026-54121) | daily.dev
description: CVE-2026-54121 (Certighost) is a vulnerability in Active Directory Certificate Services (AD CS) that allows a low-privileged domain user to impersonate a...
canonical: https://daily.dev/posts/certighost-cve-2026-54121--axfow8dnw
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Certighost (CVE-2026-54121) | daily.dev
og:description: CVE-2026-54121 (Certighost) is a vulnerability in Active Directory Certificate Services (AD CS) that allows a low-privileged domain user to impersonate a...
og:url: https://daily.dev/posts/certighost-cve-2026-54121--axfow8dnw
og:image: https://api.daily.dev/og/posts/AxFow8dNw.png
og:image:alt: Certighost (CVE-2026-54121)
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Certighost (CVE-2026-54121)

**[Abdul Rauf](https://daily.dev/sources/8bk3r1fnslw6a2yunhsln)** · [@raufus9799](https://daily.dev/raufus9799) · 1 min read · 0 upvotes · 0 comments

## Summary

CVE-2026-54121 (Certighost) is a vulnerability in Active Directory Certificate Services (AD CS) that allows a low-privileged domain user to impersonate a Domain Controller. By supplying crafted cdc and rmd request attributes during certificate enrollment, an attacker forces the Enterprise CA to query an attacker-controlled host over SMB and LDAP. The CA blindly trusts the returned directory objects (objectSid and dNSHostName of a real DC) and issues a certificate with strong identity mapping for the Domain Controller, enabling successful PKINIT authentication as the DC.

## Content

**Certighost (CVE-2026-54121) — AD CS Domain Controller Impersonation**

**Low-privileged domain user can impersonate a Domain Controller via an AD CS enrollment chase fallback. By supplying cdc (Client DC) and rmd (Remote Domain) request attributes, an attacker forces the Enterprise CA to query an attacker-controlled host over SMB and LDAP.**

**The CA then blindly trusts the returned directory objects (objectSid + dNSHostName of a real DC) and issues a certificate containing strong identity mapping for the Domain Controller. This allows successful PKINIT authentication as the DC.**

**Research:**
[https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26](https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26)

**Source:**
[https://github.com/aniqfakhrul/CVE-2026-54121](https://github.com/aniqfakhrul/CVE-2026-54121)

## Similar posts on daily.dev

- [Certighost and the Privilege Hiding in Your Certificate Authority](https://daily.dev/posts/certighost-and-the-privilege-hiding-in-your-certificate-authority-8opcdovjc) · BleepingComputer · 0 upvotes · 0 comments
- [New Certighost PoC exploit lets attackers hijack Windows domains](https://daily.dev/posts/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains-jhtwvjxyo) · BleepingComputer · 0 upvotes · 0 comments
- [Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools](https://daily.dev/posts/inside-ad-cs-escalation-unpacking-advanced-misuse-techniques-and-tools-qejabt669) · Unit 42 · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#active-directory](https://daily.dev/tags/active-directory)

[View this post on daily.dev](https://daily.dev/posts/certighost-cve-2026-54121--axfow8dnw)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"DiscussionForumPosting","mainEntityOfPage":"https://daily.dev/posts/certighost-cve-2026-54121--axfow8dnw","headline":"Certighost (CVE-2026-54121)","text":"CVE-2026-54121 (Certighost) is a vulnerability in Active Directory Certificate Services (AD CS) that allows a low-privileged domain user to impersonate a Domain Controller. By supplying crafted cdc and rmd request attributes during certificate enrollment, an attacker forces the Enterprise CA to query an attacker-controlled host over SMB and LDAP. The CA blindly trusts the returned directory objects (objectSid and dNSHostName of a real DC) and issues a certificate with strong identity mapping for the Domain Controller, enabling successful PKINIT authentication as the DC.","url":"https://daily.dev/posts/certighost-cve-2026-54121--axfow8dnw","datePublished":"2026-08-03T16:11:29.387Z","dateModified":"2026-08-03T16:11:43.003Z","author":{"@type":"Person","name":"Abdul Rauf","url":"https://daily.dev/raufus9799","image":"https://media.daily.dev/image/upload/s--OO8FyDRK--/f_auto/v1785654480/avatars/avatar_8bk3r1FnSLW6a2yUnhsLN?_a=BAMAMicg0","description":"Founder & CEO @ DEVNOX SOLUTIONS | Full-Stack Developer | AI & Cybersecurity Engineer","interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"EndorseAction"},"userInteractionCount":20}},"interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"isPartOf":{"@type":"WebPage","url":"https://daily.dev/sources/8bk3r1fnslw6a2yunhsln","name":"Abdul Rauf"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Abdul Rauf","item":"https://daily.dev/sources/8bk3r1fnslw6a2yunhsln"},{"@type":"ListItem","position":3,"name":"Certighost (CVE-2026-54121)"}]}
```

