What is CVE-2026-52686?
This vulnerability allows a DNSSEC validation bypass by accepting wildcard expansion proofs (NSEC/NSEC3 records) without proper signature validation when the wildcard answer is a CNAME or DNAME record. Affected DNS resolvers may accept spoofed responses, potentially redirecting users to malicious sites.
Azərbaycanca: Bu boşluq DNSSEC yoxlamasında yan keçməyə imkan verir. Təsdiq edilməmiş wildcard NSEC/NSEC3 sübutları, xüsusilə CNAME və ya DNAME cavabları zamanı qəbul edilir. Təsirə məruz qalan sistemlərdə DNS cavablarının bütövlüyü pozula bilər və istifadəçilər saxta ünvanlara yönləndirilə bilər, təcili yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ1
How does CVE-2026-52686 bypass DNSSEC validation?
The vulnerability bypasses DNSSEC validation by accepting wildcard expansion proofs (NSEC/NSEC3 records) without proper signature validation when the wildcard answer is a CNAME or DNAME record.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.