CVE-2026-43510

HIGH

CISA manage.get.gov insecure portfolio administrative privileges

Title source: cna
STIX 2.1

Description

manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.

References (6)

Core 6

Scores

CVSS v3 7.6
EPSS 0.0034
EPSS Percentile 26.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-266
Status published
Products (3)
CISA/manage.get.gov < 1.176.0
CISA/manage.get.gov 1.176.0
CISA/manage.get.gov 1.92.0 - 1.176.0
Published May 07, 2026
Tracked Since May 08, 2026