Start with Identity

CVE-2026-27912ResetNightmare, kpasswd bypasses PAC_REQUESTOR_SID

high
Product: Active Directory (kpasswd)Vendor: MicrosoftDisclosed: 2026-04-14Status: PatchedNVD ↗

What broke

The Kerberos change-password path (kpasswd) did not apply PAC_REQUESTOR_SID the way ticket-granting did. A user who can write their own UPN can aim a password reset at a Domain Admin. Microsoft rated it Important and patched in April 2026. The research name is ResetNightmare.

Why it matters

"Important" from MSRC is not the same as "low priority." A low-priv user resetting DA is a domain-compromise bug that happens to sit on a less glamorous protocol (kpasswd, not TGS). UPN self-write is also more common than people think: help-desk tools, self-service, and poorly scoped ACL inheritances.

What to do

  • Patch DCs for April 2026.
  • Remove Write property (UPN) from users who do not need it. Audit who can write userPrincipalName on privileged accounts.
  • Monitor kpasswd / password-change events on admin accounts that did not go through your PAM or help-desk flow.

After you patch

Active Directory compromise is not contained by patching, because the artifacts an attacker creates outlive the vulnerability.

  • Rotate the krbtgt account twice, with the replication interval between rotations, if there is any indication of ticket forgery. One rotation is not enough.
  • Audit AD CS certificate templates for enrolment and enrollee-supplied-subject permissions, which are the most common escalation path left behind. See certificate lifecycle.
  • Review privileged group membership and delegation rights (Domain Admins, DnsAdmins, constrained and resource-based constrained delegation) for changes during the window.
  • Hunt for tickets with anomalous lifetimes or encryption types, and for authentications to services that identity never touches.
  • Treat any issued certificate as a durable credential: revoking a user's password does not revoke a certificate that authenticates as them. See privilege escalation and lateral movement.

Sources

Last reviewed By SWI Community TeamSuggest a correctionHow we research

Technique

This CVE is an instance of Kerberos delegation abuse. Delegation lets a service act as the user who called it, which is necessary for multi-tier applications and dangerous the moment the service or the delegation scope is not exactly what an administrator intended.

Know a primary source we should add, or a patch status that has changed? Email community@startwithidentity.com. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.