Description
For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature to send unauthorized zone contents to a secondary server. Although no TSIG signature ever arrives, `named` does not rollback to the pre-transfer state. To exploit the vulnerability, the transfer must be a multi-message TCP IXFR, as described by RFC 8945.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized zone updates due to TSIG verification bypass
Action: Immediate Patch
AI Analysis

Impact

A secondary BIND server may accept and apply incremental zone transfer data before the TSIG signature message is received, allowing an attacker without a valid signature to deliver malicious zone contents. The server does not revert to its pre‑transfer state when the final signed packet never arrives, which creates a state where unauthorized records are live in the zone.

Affected Systems

ISC BIND 9 running any of the following editions impacts the vulnerability: versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, the corresponding -S1 release lines, and all earlier 9.11.3–9.18.50‑S1 and 9.20.9‑27‑S1 builds.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, but the EPSS score of less than 1% shows a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalogue. Exploitation requires a multi‑message TCP IXFR transfer against a secondary that trusts TSIG authentication, and the attacker must be able to initiate the transfer. Because the final signature is never verified before the data becomes live, the attack raises the impact to integrity and availability, though it does not provide remote code execution.

Generated by OpenCVE AI on September 18, 2026 at 00:17 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Upgrade BIND 9 to a patched release (9.20.29, 9.21.26, or the 9.20.29‑S1 build) as soon as possible.
  • Temporarily disable or restrict IXFR zone transfers from untrusted IPs until the upgrade is applied.
  • Re‑verify zone‑transfer ACLs so that only authenticated, trusted servers can initiate transfers, and ensure TSIG is checked before any changes are made.
  • Enable activity logging and routinely audit zone files for unexpected modifications to detect any unauthorized updates.

Generated by OpenCVE AI on September 18, 2026 at 00:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6505-1 bind9 security update
History

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-347
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature to send unauthorized zone contents to a secondary server. Although no TSIG signature ever arrives, `named` does not rollback to the pre-transfer state. To exploit the vulnerability, the transfer must be a multi-message TCP IXFR, as described by RFC 8945. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Title Unauthenticated IXFR deltas are applied to the live zone before TSIG verification
First Time appeared Isc
Isc bind
Weaknesses CWE-349
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T17:36:48.716Z

Reserved: 2026-08-06T04:18:09.842Z

Link: CVE-2026-19033

cve-icon Vulnrichment

Updated: 2026-09-17T17:36:44.959Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:33.393

Modified: 2026-09-17T18:16:38.860

Link: CVE-2026-19033

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T14:10:08Z

Links: CVE-2026-19033 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:30:16Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature

  • CWE-349

    Acceptance of Extraneous Untrusted Data With Trusted Data