Zone Manipulation Vulnerability in BIND by ISC
CVE-2026-78301

5.8MEDIUM

Key Information:

Vendor

Isc

Status
Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-78301?

A malformed zone containing NS or DNAME nodes positioned above its origin can lead to unauthorized zone cuts in BIND authoritative servers. If an attacker inserts this malformed zone through a zone transfer, it can compromise the authoritative response for queries within the configured zone, redirecting them to potentially dangerous out-of-zone delegations. In recursion-enabled servers, BIND can cache these attacker-supplied responses, creating vulnerabilities beyond the configured zone. This issue persists as long as the malformed zone remains active in the database, highlighting significant security implications for DNS management.

Affected Version(s)

BIND 9 9.11.0 <= 9.18.50

BIND 9 9.20.0 <= 9.20.27

BIND 9 9.21.0 <= 9.21.25

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ISC would like to thank Henrique Pereira for bringing this vulnerability to our attention.
.