CVE-2026-43510
HIGHCISA manage.get.gov insecure portfolio administrative privileges
Title source: cnaDescription
manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.
References (6)
Core 6
Core References
Vendor Advisory vendor-advisory
url
https://github.com/cisagov/manage.get.gov/security/advisories/GHSA-6wrg-x3j6-x464
Government Resource, Third Party Advisory government-resource
third-party-advisory
url
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-121-01.json
Scores
CVSS v3
7.6
EPSS
0.0034
EPSS Percentile
26.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-266
Status
published
Products (3)
CISA/manage.get.gov
< 1.176.0
CISA/manage.get.gov
1.176.0
CISA/manage.get.gov
1.92.0 - 1.176.0
Published
May 07, 2026
Tracked Since
May 08, 2026