Command injection in PowerDNS Authoritative - CVE-2026-42000
Published: May 20, 2026
PowerDNS Authoritative
Detailed vulnerability description
The vulnerability allows a remote attacker to modify backend configuration.
The vulnerability exists due to command injection in Bind backend AXFR name handling when processing an AXFR of a zone with specific contents. A remote attacker can provide a zone transfer containing names with special characters to modify backend configuration.
This issue affects AXFR operations involving the Bind backend and can cause the written configuration to become non-parsable until manual correction is performed.