Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-52754

Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repository access controls, exfiltrate shared reverse engineering databases, and permanently compromise server integrity.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.1%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-52754
  • Nsa » Ghidra » Version: Any
    cpe:2.3:a:nsa:ghidra:*


Contact Us

Shodan ® - All rights reserved