Certighost and the Privilege Hiding in Your Certificate Authority
Summary
A newly disclosed vulnerability, CVE-2026-54121, allows a standard domain user to compromise an Enterprise Certificate Authority, effectively turning it into a Domain Controller. The article emphasizes that while patching is straightforward, the real lesson lies in understanding standing privileges, implicit trust, and recognizing PKI's critical role as Tier 0 identity infrastructure.
IFF Assessment
This vulnerability grants attackers a significant escalation of privileges within an organization's network, enabling them to seize control of sensitive identity infrastructure.
Severity
Defender Context
This vulnerability highlights the critical importance of securing Certificate Authorities (CAs) as Tier 0 assets. Defenders must implement strict access controls and monitoring for PKI infrastructure, as compromise can lead to widespread domain compromise. Understanding and mitigating implicit trust within PKI is essential for robust identity and access management.