Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse
2026-04-01T07:23:32Z•1e362ffb9349d58ef4f18841f103c009b885645b3fa2e63372b085309bc46617
Active DirectoryAuthentication relayCNAME abuseCVE-2026-20929DNSDelegationDetectionIdentity theftKDCKerberosMitigationRelay attackService Principal Name
What happened
CrowdStrike published detection guidance for CVE-2026-20929, a Kerberos authentication-relay technique that abuses DNS CNAME records to facilitate Kerberos relay/impersonation in Active Directory environments. The advisory focuses on detection and mitigation controls for identifying CNAME-based referral abuse, hardening Kerberos delegation and SPNs, and monitoring related DNS and KDC activity to reduce risk of account impersonation and lateral movement.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- crowdstrike_blog
- Record identifier
- 1e362ffb9349d58ef4f18841f103c009b885645b3fa2e63372b085309bc46617
- Enrichment time
- 2026-04-01T07:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.