Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 10 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repository access controls, exfiltrate shared reverse engineering databases, and permanently compromise server integrity. | |
| Title | Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModule | |
| First Time appeared |
Nsa
Nsa ghidra |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nsa
Nsa ghidra |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-10T13:53:32.074Z
Reserved: 2026-06-08T15:20:09.274Z
Link: CVE-2026-52754
Updated: 2026-06-10T13:53:21.784Z
Status : Analyzed
Published: 2026-06-10T14:16:35.603
Modified: 2026-06-11T19:52:14.750
Link: CVE-2026-52754
No data.
OpenCVE Enrichment
Updated: 2026-06-11T10:42:10Z