Insufficient verification of data authenticity in ISC BIND - CVE-2026-19941

 

Insufficient verification of data authenticity in ISC BIND - CVE-2026-19941

Published: September 16, 2026


Vulnerability identifier: #VU150223
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-19941
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to poison the DNS cache.

The vulnerability exists due to insufficient verification of data authenticity in the checkwildcard() function of the named resolver when validating wildcard-nonexistence proofs. A remote attacker can provide an out-of-zone NSEC record as proof that a wildcard does not exist to poison the DNS cache.

Exploitation requires control at the same or an upstream level of the zone name.


Affected software

ISC BIND

How to mitigate CVE-2026-19941

Install security update from vendor's website.

ISC BIND - addressed in versions 9.20.29, 9.20.29-s1, 9.21.26

External References

Related Security Bulletins