A published proof of concept for ResetNightmare (CVE-2026-27912) reportedly allows attackers to reset another user or computer account’s password on unpatched Active Directory domain controllers without knowing the existing password. The Kerberos Change Password validation flaw requires an attacker-controlled account with WriteProperty permission on its own userPrincipalName (UPN) attribute. The attack changes that UPN to spoof a target identity, obtains a Kerberos ticket using NT-ENTERPRISE and the kadmin/changepw service, clears the UPN, and resets the target password. The implementation uses ResetNightmare.ps1, the ActiveDirectory PowerShell module, and Rubeus.exe. The report provides no evidence of exploitation in the wild and cautions that its automatically extracted indicators were not externally verified.
Splunk has published a detection for the attack’s setup stage that searches Windows Security Event 4738 for accounts modifying their own UPN to a value without an @ sign, excluding placeholders and selected system identities. The analytic requires domain-controller security logs and User Account Management auditing, is disabled by default, and can flag legitimate provisioning or migration activity. Security teams should verify domain-controller patch status, review permissions allowing accounts to modify their own UPN, and enable and tune the detection against normal account-management workflows. Suspicious matches warrant investigation for subsequent password changes and potential account takeover.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk updated its Windows AD User Suspicious UPN Change detection to identify account self-modifications associated with ResetNightmare (CVE-2026-27912). The analytic examines Windows Security Event 4738 for suspicious UPN values without an @ sign and requires Domain Controller account-management audit logs.
A published proof of concept demonstrates how CVE-2026-27912 can enable unauthorized password resets for target user or computer accounts on unpatched Active Directory domain controllers. It manipulates an attacker-controlled account's userPrincipalName and obtains a Kerberos kadmin/changepw ticket; exploitation requires permission to modify that account's UPN.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceresearch.splunk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.