CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Certighost and the Privilege Hiding in Your Certificate Authority

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4506

As cited

Copy frozen at (site build).

vulnerabilities

Certighost and the Privilege Hiding in Your Certificate Authority

CVE-2026-54121 allows a standard domain user to elevate privileges and convert an Enterprise Certificate Authority (CA) into a Domain Controller. The vulnerability highlights the risks of standing privilege and implicit trust in PKI systems that should be treated as Tier 0 identity infrastructure.

Why it matters: Organizations running Enterprise CA should assess whether standard users have unintended access paths to CA systems; this affects domain security fundamentally since CAs underpin identity trust.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Certighost and the Privilege Hiding in Your Certificate Authority

CVE-2026-54121 allows a standard domain user to elevate privileges and convert an Enterprise Certificate Authority (CA) into a Domain Controller. The vulnerability highlights the risks of standing privilege and implicit trust in PKI systems that should be treated as Tier 0 identity infrastructure.

Why it matters: Organizations running Enterprise CA should assess whether standard users have unintended access paths to CA systems; this affects domain security fundamentally since CAs underpin identity trust.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary