Description
A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone then lose authoritative status and return an out-of-zone delegation. On a server that also provides recursion BIND can follow this locally sourced cut and cache attacker-supplied data, affecting names outside the configured zone. This situation persists as long as the malformed zone remains in the zone database.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: DNS Spoofing
Action: Patch Immediately
AI Analysis

Impact

This vulnerability allows an attacker to craft a malformed DNS zone that contains an NS or DNAME node positioned above the zone origin. When named loads such a zone, it interprets the node as a zone cut, effectively truncating the zone at that point. As a result, queries for names that are actually inside the intended zone lose authoritative status and receive answers that originate from the injected zone cut. On a server providing recursion, named will follow this locally generated cut, cache the attacker’s data, and serve it for queries outside the configured zone. This can lead to DNS data spoofing and potentially redirect or downgrade DNS traffic for domains that rely on the server’s recursion.

Affected Systems

The flaw affects ISC BIND 9 versions from 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3‑S1 through 9.18.50‑S1, and 9.20.9‑S1 through 9.20.27‑S1, which includes all actively maintained releases up to the latest Stable‑S1 platforms. The affected product is the ISC BIND 9 authoritative DNS server.

Risk and Exploitability

The CVSS base score of 5.8 indicates moderate severity; the EPSS score of less than 1% suggests a low probability that the vulnerability will be exploited in the near term. It is not registered in the CISA KEV catalog today. An attacker would need the ability to introduce a crafted zone file—through zone transfer, the web‑based administration interface, or direct file editing on the server—and then trigger a reload of the zone. Once the malformed zone is present, the effect lasts until the zone file is corrected or the server is restarted. Because DNS data is being overwritten for all domains under the cut, affected clients could receive false information, leading to redirection or denial of service against domains that were not intended to be controlled by the attacker.

Generated by OpenCVE AI on September 18, 2026 at 02:36 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Upgrade to the latest patched release of BIND 9: 9.20.29, 9.21.26, or 9.20.29‑S1, depending on the current version.
  • Restrict zone transfer and administrative access to known, trusted IP addresses, and enforce authentication to prevent unauthorized zone injection.
  • Use the BIND tool named-checkzone to validate zone files before deployment, ensuring no NS or DNAME nodes occur above the zone origin that would create an unintended zone cut.

Generated by OpenCVE AI on September 18, 2026 at 02:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-168
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 16 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone then lose authoritative status and return an out-of-zone delegation. On a server that also provides recursion BIND can follow this locally sourced cut and cache attacker-supplied data, affecting names outside the configured zone. This situation persists as long as the malformed zone remains in the zone database. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Title Out-of-zone database nodes can become authoritative zone cuts
First Time appeared Isc
Isc bind
Weaknesses CWE-349
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T18:43:12.526Z

Reserved: 2026-08-24T07:52:08.223Z

Link: CVE-2026-78301

cve-icon Vulnrichment

Updated: 2026-09-17T18:43:07.666Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:10.400

Modified: 2026-09-17T19:16:59.937

Link: CVE-2026-78301

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T13:58:11Z

Links: CVE-2026-78301 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:45:17Z

Weaknesses
  • CWE-168

    Improper Handling of Inconsistent Special Elements

  • CWE-349

    Acceptance of Extraneous Untrusted Data With Trusted Data