In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.
[POC] GHSA-652q-gvq3-74qv — CVE-2026-54121
Certighost POC
[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-54121-CertiGhost
CVE-2026-54121(CertiGhost) without MachineAccountQuota POC
[POC] GHSA-652q-gvq3-74qv — CVE-2026-54121
CVE-2026-54121
[POC] GHSA-8gj2-2cvc-6xx7 — Certighost-CVE-2026-54121
Splunk detection writeup for CVE-2026-54121 (CertiGhost): AD CS certificate chase abuse leading to full domain compromise. Lab-validated detection, triage steps, and incident investigation against a live DC.
[POC] GHSA-652q-gvq3-74qv — CVE-2026-54121
CVE-2026-54121 - Draft
[POC] GHSA-652q-gvq3-74qv — CVE-2026-54121-PoC-Exploit
👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework ⚡Weaponized tool with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒
[POC] GHSA-3whf-vgf2-9w6g — Metasploit-CVE-2026-54121-Certighost
A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase" fallback. The CA can be coerced into authenticating back to attacker-controlled infrastructure and then issuing a certificate that impersonates a Domain Controller.
[POC] GHSA-6vch-q96h-7gc3 — certighost-cve-2026-54121-slides
Slidev presentation for Certighost (CVE-2026-54121), with Mermaid diagrams and exported assets.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free