CVE-2026-26017 describes a logical vulnerability in CoreDNS versions prior to 1.14.2, allowing DNS access controls to be bypassed. This high-severity flaw (CVSS 7.7) stems from a Time-of-Check Time-of-Use (TOCTOU) issue where security plugins are evaluated before the rewrite plugin, enabling unauthorized access to DNS resources. The attack vector is network-based with low complexity, potentially leading to high confidentiality impact. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.14.2CPE matchmatch criteria | cpe:2.3:a:coredns.io:coredns:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.