# ResetNightmare, kpasswd bypasses PAC_REQUESTOR_SID

Source: https://startwithidentity.com/cves/cve-2026-27912/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

The Kerberos change-password path (kpasswd) did not apply `PAC_REQUESTOR_SID` the way ticket-granting did. A user who can write their own UPN can aim a password reset at a Domain Admin. Microsoft rated it Important and patched in April 2026. The research name is ResetNightmare.

## Why it matters

"Important" from MSRC is not the same as "low priority." A low-priv user resetting DA is a domain-compromise bug that happens to sit on a less glamorous protocol (kpasswd, not TGS). UPN self-write is also more common than people think: help-desk tools, self-service, and poorly scoped ACL inheritances.

## What to do

- Patch DCs for April 2026.
- Remove `Write property (UPN)` from users who do not need it. Audit who can write `userPrincipalName` on privileged accounts.
- Monitor kpasswd / password-change events on admin accounts that did not go through your PAM or help-desk flow.

## After you patch

Active Directory compromise is not contained by patching, because the artifacts an attacker creates outlive the vulnerability.

- **Rotate the krbtgt account twice**, with the replication interval between rotations, if there is any indication of ticket forgery. One rotation is not enough.
- **Audit AD CS certificate templates** for enrolment and enrollee-supplied-subject permissions, which are the most common escalation path left behind. See [certificate lifecycle](https://startwithidentity.com/glossary/certificate-lifecycle/).
- **Review privileged group membership and delegation rights** (Domain Admins, DnsAdmins, constrained and resource-based constrained delegation) for changes during the window.
- **Hunt for tickets with anomalous lifetimes or encryption types**, and for authentications to services that identity never touches.
- **Treat any issued certificate as a durable credential**: revoking a user's password does not revoke a certificate that authenticates as them. See [privilege escalation](https://startwithidentity.com/glossary/privilege-escalation/) and [lateral movement](https://startwithidentity.com/glossary/lateral-movement/).

## Sources

- [NVD: CVE-2026-27912](https://nvd.nist.gov/vuln/detail/CVE-2026-27912)
