CVE-2026-43510

7.6

CISA · manage.get.gov

An incorrect privilege assignment vulnerability in CISA manage.get.gov allows organization administrators to improperly assign domain manager privileges.

Executive summary

An incorrect privilege assignment vulnerability in the CISA manage.get.gov registrar allows high privileged organization administrators to improperly assign domain manager privileges, potentially leading to unauthorized domain control.

Vulnerability

This is an incorrect privilege assignment vulnerability categorized under CWE-266, which can be triggered by authenticated organization administrators over the network.

Business impact

A successful exploit could allow malicious or compromised administrators to improperly assign domain manager privileges for domains outside their legitimate scope, leading to unauthorized domain control and management. This undermines the integrity of domain registrations within the TLD registrar. The CVSS score of 7.6 indicates a high severity rating primarily due to the potential for severe integrity and availability impacts on downstream systems.

Remediation

Immediate Action: Update manage.get.gov to version 1.176.0 or later to resolve the privilege assignment flaw.

Proactive Monitoring: Review administrative audit logs regularly for unauthorized changes to domain manager assignments and privilege allocations.

Compensating Controls: Enforce strict access control policies and the principle of least privilege for organization administrator accounts while planning the update.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations utilizing the manage.get.gov platform must prioritize updating to version 1.176.0 to eliminate the privilege assignment risk. Reviewing existing domain manager assignments immediately after patching will ensure no unauthorized privileges persist within the environment.

Sources

Originally found and disclosed by bn-omran (@scofaild23), per the CVE Program record.

  • url Patch commit
  • url Release notes
  • url Vendor advisory
  • url Vulnerability database entry
  • url Third-party advisory
  • url Issue tracker
  • url