What happened
An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.
Affected versions
Active Directory: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
SploitusAD CS elevation of privilege via Machine template DNS Name impersonating a Domain Controller.KitPloit2026-09-12T15:06:29Candidatekitploit.comAD CS elevation of privilege via Machine template DNS Name impersonating a Domain Controller.ru2026-09-12T15:06:29CandidatePoC-in-GitHub · r1skkam/TryHackMe-CVE-2022-26923Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services★ 6r1skkam2022-05-12CandidatePoC-in-GitHub · LudovicPatho/CVE-2022-26923_AD-Certificate-ServicesThe vulnerability allowed a low-privileged user to escalate privileges to domain administrator in a default Active Directory environment with the Active Directory Certificate Services (AD CS) server role installed.★ 41LudovicPatho2022-05-14CandidatePoC-in-GitHub · lsecqt/CVE-2022-26923-Powershell-POCA powershell poc to load and automatically run Certify and Rubeus from memory.★ 17lsecqt2022-08-17CandidatePoC-in-GitHub · evilashz/PIGADVulnScanner检测域内常见一把梭漏洞,包括:NoPac、ZeroLogon、CVE-2022-26923、PrintNightMare★ 82evilashz2023-10-17CandidatePoC-in-GitHub · Gh-Badr/CVE-2022-26923A proof of concept exploiting CVE-2022-26923.★ 2Gh-Badr2023-11-28CandidatePoC-in-GitHub · Yowise/CVE-2022-26923★ 0Yowise2024-09-01CandidatePoC-in-GitHub · rayngnpc/CVE-2022-26923-rayngExploitation for CVE-2022-26923★ 0rayngnpc2025-03-04CandidatePoC-in-GitHub · Eliasdekiniweek/CVE-2022-26923Exploitation de CVE-2022-26923★ 1Eliasdekiniweek2026-02-21CandidatePoC-in-GitHub · Nefhara/CVE-2022-26923Automated CVE-2022-26923 Exploitation (Certifried)★ 0Nefhara2026-05-29CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.