CVE-2026-52754: Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModule
Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repository access controls, exfiltrate shared reverse engineering databases, and permanently compromise server integrity.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghidrato a version that resolves this vulnerability.Fixed in 12.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-52754?
CVE-2026-52754 has a severity rating of high, with a score of 8.7.
What does CVE-2026-52754 vulnerability affect?
CVE-2026-52754 affects Ghidra versions prior to 12.1, specifically in the PKIAuthenticationModule.
How do I fix CVE-2026-52754?
To fix CVE-2026-52754, you should apply the available patch for Ghidra.
What is the impact of CVE-2026-52754?
CVE-2026-52754 allows attackers to bypass authentication and impersonate other users using a valid CA-signed certificate.
Who is affected by CVE-2026-52754?
Any user of Ghidra versions below 12.1 who relies on the PKIAuthenticationModule is at risk from CVE-2026-52754.