CORS Misconfiguration in PowerDNS Affects Administrator Dashboard Security
CVE-2026-0397
3.1LOW
What is CVE-2026-0397?
A vulnerability in PowerDNS allows attackers to exploit the misconfiguration of the Cross-Origin Resource Sharing (CORS) policy. When the internal webserver is enabled, it can trick administrators logged into the dashboard into visiting a malicious website. This could lead to unauthorized access to sensitive information about the running configuration of PowerDNS instances, potentially compromising system integrity.
Affected Version(s)
DNSdist 1.9.0 < 1.9.12
DNSdist 2.0.0 < 2.0.3
