PT-2026-23721 · Coredns+1 · Coredns+1

·

CVE-2026-26017

·

Published

2026-03-06

·

Updated

2026-07-30

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CoreDNS versions prior to 1.14.2
Description A logical flaw exists due to the default execution order of plugins, where security plugins such as acl are evaluated before the rewrite plugin. This creates a Time-of-Check Time-of-Use (TOCTOU) flaw—a race condition where a resource is checked but then modified before it is used—allowing attackers to bypass DNS access controls. In multi-tenant Kubernetes clusters, this can undermine DNS-based segmentation, enabling unauthorized service discovery and reconnaissance of restricted internal infrastructure by mapping public names to internal services after the access control check has passed.
Recommendations Update to version 1.14.2. Reorder the default plugin.cfg so that rewrite and other normalization plugins run before acl, opa, and firewall. Ensure all access control checks are applied after name normalization.

Exploit

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-79497
AZL-79526
BDU:2026-12011
CLEANSTART-2026-VJ54611
CVE-2026-26017
GHSA-C9V3-4PV7-87PR
GO-2026-4630
OESA-2026-2939
OESA-2026-3062
OESA-2026-3064
OESA-2026-3065
OESA-2026-3066
OPENSUSE-SU-2026:10297-1
OPENSUSE-SU-2026:20619-1
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1042-1

Affected Products

Coredns
Red Os