Executive brief
Ghidra is a software reverse engineering suite used by security researchers to analyze code. A vulnerability in its server component allows a user with a valid digital certificate to impersonate any other user, including administrators, without knowing their password or private key. This could allow an attacker to steal sensitive research data, delete shared project databases, or take full control of the server's access settings.
Technical details
An authentication bypass vulnerability exists in GhidraServer's PKIAuthenticationModule.authenticate() due to improper verification of cryptographic signatures (CWE-347). When the server is configured in PKI mode (-a2), it uses a challenge-response protocol where the client is expected to sign a random token. However, the server-side logic skips the signature verification block entirely if the signature bytes provided by the client are null, rather than rejecting the request. An attacker with a valid CA-signed certificate can present any other user's public certificate and a null signature to successfully authenticate as that user. This allows for privilege escalation to administrator status and full access to shared repositories. The issue is fixed in Ghidra version 12.1.
Affected products
- National Security Agency (NSA) Ghidra Server < 12.1
Timeline
- 2019-03-26: other: Vulnerability introduced in initial open-source release
- 2026-05-14: advisory: GitHub Security Advisory GHSA-5wxq-7qpv-65p2 published
- 2026-06-10: disclosed: CVE-2026-52754 published to NVD
References
- https://github.com/NationalSecurityAgency/ghidra/commit/78729379e471bbb3d969409be6a8c3d24af84220
- https://github.com/NationalSecurityAgency/ghidra/commit/79d8f164f8bb8b15cfb60c5d4faeb8e1c25d15ca
- https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-5wxq-7qpv-65p2
- https://www.vulncheck.com/advisories/ghidra-authentication-bypass-via-null-signature-in-pkiauthenticationmodule