Sceawere

Vulnerability Detail

CVE-2026-13321Updated Verified Sceawere Triage Sources: NVD / CISA KEV

BIND DNSSEC NSEC Validation Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
6h ago
Vendor
ISC
Product
BIND 9
Attack Type
CWE-346 Origin Validation Error
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-07-22T15:16:52.200Z",
  "pubdate": "2026-07-22T15:16:52.200Z",
  "executiveSummary": "An input validation vulnerability exists within the DNSSEC validation component of the BIND resolver.\nThe vulnerability specifically arises because the BIND resolver improperly accepts validly-signed NSEC records where the Next Domain Name field points outside of the authorized signer's zone.\nThis flaw impacts multiple BIND 9 branches, specifically versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.\nSuccessful exploitation of this issue allows an attacker to bypass critical DNSSEC validation checks, potentially leading to the acceptance of forged or malicious DNS data as authentic.\nThe risk implication involves compromised DNS integrity and potential redirection or spoofing attacks against clients relying on the affected resolver.\nExploitation requires the attacker to have the ability to supply or influence signed NSEC records that cross zone boundaries during resolution processes.",
  "technicalDetails": "The vulnerability resides in the BIND resolver component responsible for parsing and validating DNSSEC NSEC records.\nThe root cause is an insufficient boundary check concerning the Next Domain Name field within NSEC resource records.\nWhen processing a validly-signed response, the resolver fails to verify whether the Next Domain Name properly resides within the administrative boundaries of the signer's zone.\nDuring the attack flow, a malicious or compromised authoritative name server provides a crafted NSEC record containing a Next Domain Name pointing outside the legitimate zone.\nThe vulnerable BIND resolver processes this record, incorrectly trusts the cryptographic signature, and bypasses standard zone closure validations.\nThis network-exposed flaw can be triggered remotely without authentication or high privilege requirements, provided the resolver queries the malicious zone controlled by the attacker.\nThe post-exploitation impact includes the potential subversion of DNS security guarantees, allowing attackers to manipulate negative caching or assertion mechanisms and compromise the resolution chain for targeted domains."
}
CVE-2026-13321: BIND DNSSEC NSEC Validation Bypass (HIGH Severity, CVSS: 8.6) - Sceawere