Description
A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: DNS Spoofing
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises when ISC BIND 9 accepts a validly signed NSEC3 record from an unrelated sibling zone as formal proof of non‑existence for a queried name, allowing an attacker to forge unsigned DNS answers that bypass the zone’s secure delegation. This flaw is rooted in improper authorization checks (CWE‑290) and misuse of trust references (CWE‑346). The effect is that a resolver may receive an unsolicited response that appears authentic, potentially redirecting client traffic or providing false data.

Affected Systems

The flaw is present in ISC BIND 9 firmware versions 9.11.0 to 9.18.50, 9.20.0 to 9.20.27, 9.21.0 to 9.21.25, and their corresponding patch‑level releases 9.11.3‑S1 to 9.18.50‑S1, 9.20.9‑S1 to 9.20.27‑S1. Any server running these ranges is impacted, and administrators should verify that their BIND installation is not within these version ranges.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% suggests a very low observed exploitation probability. The vulnerability is not listed in the CISA KEV catalog, and no public exploitation reports exist. An attacker would need to trick a resolver into using a cached NSEC3 RRset; therefore active exploitation is currently unlikely, but mitigations are advisable to protect against potential future abuse.

Generated by OpenCVE AI on September 18, 2026 at 02:29 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Upgrade BIND to the latest patched release specified by ISC (9.20.29, 9.21.26, or 9.20.29‑S1).
  • After upgrading, ensure DNSSEC validation is enabled for all zones so that only signed NSEC3 responses from the authoritative zone are accepted, addressing the improper authorization weakness.
  • Perform a DNSSEC audit and monitor the server for any anomalous NSEC3 responses from unrelated zones to confirm the flaw has been neutralized.

Generated by OpenCVE AI on September 18, 2026 at 02:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6505-1 bind9 security update
History

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Title NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets
First Time appeared Isc
Isc bind
Weaknesses CWE-346
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T18:39:41.607Z

Reserved: 2026-08-20T12:48:33.514Z

Link: CVE-2026-77119

cve-icon Vulnrichment

Updated: 2026-09-17T18:39:37.187Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:46.427

Modified: 2026-09-17T19:16:59.490

Link: CVE-2026-77119

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T14:17:11Z

Links: CVE-2026-77119 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:30:06Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-346

    Origin Validation Error