Home

Description

Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repository access controls, exfiltrate shared reverse engineering databases, and permanently compromise server integrity.

PUBLISHED Reserved 2026-06-08 | Published 2026-06-10 | Updated 2026-06-10 | Assigner VulnCheck




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

Improper Verification of Cryptographic Signature

Product status

Default status
unaffected

Any version before 12.1
affected

12.1 (custom)
unaffected

Credits

@jro-calif reporter

Sean Nejad (@allsmog) finder

References

github.com/...ghidra/security/advisories/GHSA-5wxq-7qpv-65p2 (GitHub Security Advisory (GHSA-5wxq-7qpv-65p2)) vendor-advisory

github.com/...ommit/78729379e471bbb3d969409be6a8c3d24af84220 (Patch Commit (1)) patch

github.com/...ommit/79d8f164f8bb8b15cfb60c5d4faeb8e1c25d15ca (Patch Commit (2)) patch

www.vulncheck.com/...ll-signature-in-pkiauthenticationmodule third-party-advisory

cve.org (CVE-2026-52754)

nvd.nist.gov (CVE-2026-52754)

Download JSON