ResetNightmare is Semperis’s name for its proof of concept for CVE-2026-27912, a Windows Kerberos authorization flaw in the password-change path. Semperis reports that a low-privileged domain principal can reset another user or computer account password without knowing the current one when particular Active Directory permissions are present.
A reset of a sensitive account can grant access that should not exist. A reset of a privileged account can turn a limited foothold into a domain-wide incident. Patch domain controllers and review the directory permissions that make the condition reachable.
Microsoft rates the issue 8.0 (High) and identifies improper authorization as the weakness. The public Semperis report describes two conditions: an unpatched domain controller and a principal that can control a user principal name on an account it owns, or create a user or computer account in a suitably delegated organisational unit.
Check first for domain controllers on an affected build. Then identify ordinary users, service identities, and delegated support groups with broader-than-intended write or account-creation rights in Active Directory.
Use the Microsoft Security Update Guide entry to identify the update for each supported Windows Server release. Confirm coverage on every writable domain controller, including disaster-recovery and regional systems.
Review delegated rights now, rather than waiting for the next broad access review. Check the ability to write user principal names, GenericWrite-style delegation, and the rights to create users or computers in delegated organisational units. Onboarding and automation permissions often outlive the task that justified them.
- Patch every affected domain controller using the Microsoft advisory for CVE-2026-27912.
- Inventory delegated Active Directory rights around user principal names, broad write permissions, and account creation.
- Review unexpected password resets alongside nearby account and directory changes, especially when the target is privileged or operationally sensitive.
- Escalate an unexplained reset of a privileged account as a possible credential-compromise event, then rotate dependent credentials and investigate the account activity.
The NVD record lists Microsoft CNA’s 8.0 High score. Its CISA SSVC entry, recorded in April, lists no known exploitation and says the flaw is not automatable. SSVC status can change, and loose delegation gives an attacker a route from a low-privileged account to a valuable target.
Put the domain-controller patch and a targeted permissions review on the current operational queue. Prioritise low-privileged principals with the relevant directory rights. The cited sources do not establish mass exploitation.
Broadsheet will track changes to Microsoft’s advisory, the NVD record, and exploitation status. Keep the Windows Server products behind your domain controllers in your tracked stack, and record an owner for delegated Active Directory paths.
