CVE-2026-43510
7.6CISA · manage.get.gov
An incorrect privilege assignment vulnerability in CISA manage.get.gov allows organization administrators to improperly assign domain manager privileges.
Executive summary
An incorrect privilege assignment vulnerability in the CISA manage.get.gov registrar allows high privileged organization administrators to improperly assign domain manager privileges, potentially leading to unauthorized domain control.
Vulnerability
This is an incorrect privilege assignment vulnerability categorized under CWE-266, which can be triggered by authenticated organization administrators over the network.
Business impact
A successful exploit could allow malicious or compromised administrators to improperly assign domain manager privileges for domains outside their legitimate scope, leading to unauthorized domain control and management. This undermines the integrity of domain registrations within the TLD registrar. The CVSS score of 7.6 indicates a high severity rating primarily due to the potential for severe integrity and availability impacts on downstream systems.
Remediation
Immediate Action: Update manage.get.gov to version 1.176.0 or later to resolve the privilege assignment flaw.
Proactive Monitoring: Review administrative audit logs regularly for unauthorized changes to domain manager assignments and privilege allocations.
Compensating Controls: Enforce strict access control policies and the principle of least privilege for organization administrator accounts while planning the update.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Organizations utilizing the manage.get.gov platform must prioritize updating to version 1.176.0 to eliminate the privilege assignment risk. Reviewing existing domain manager assignments immediately after patching will ensure no unauthorized privileges persist within the environment.
Sources
Originally found and disclosed by bn-omran (@scofaild23), per the CVE Program record.