Junglewise Threat Intelligence

CVE-2026-52686: PowerDNS Recursor DNSSEC validation bypass in wildcard CNAME/DNAME records

CVE-2026-52686 · Severity: low · CVSS 3.7 · Published 2026-07-23

Technologies: Powerdns Recursor. Vendors: Powerdns.

Executive brief

PowerDNS Recursor, a service used to look up internet addresses, contains a flaw in how it verifies secure website records. An attacker could potentially bypass security checks (DNSSEC) to provide incorrect address information when specific record types like CNAME or DNAME are used. While this could lead to users being directed to the wrong destination, the attack is difficult to execute and does not directly expose private data.

Technical details

A DNSSEC validation bypass exists in PowerDNS Recursor's DNSSEC validation module, specifically within 'syncres.cc'. The vulnerability occurs when the recursor processes wildcard expansion proofs (NSEC or NSEC3 records); it fails to perform proper signature validation if the resulting wildcard answer is a CNAME or DNAME record. A remote attacker can exploit this to inject unvalidated DNS data into the cache. The attack requires a high degree of complexity to successfully time and spoof the necessary records. Patches are available in versions 5.2.12, 5.3.9, and 5.4.4.

Affected products

  • PowerDNS Recursor 5.2.0 to 5.2.11, 5.3.0 to 5.3.8, 5.4.0 to 5.4.3

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats