CVE-2026-43510
CISA manage.get.gov insecure portfolio administrative privileges
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.1EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
07 may 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H
Productos afectados
CISA · manage.get.gov¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://github.com/cisagov/manage.get.gov/issues/4858https://github.com/cisagov/manage.get.gov/pull/4900https://github.com/cisagov/manage.get.gov/releases/tag/v1.176.0https://github.com/cisagov/manage.get.gov/security/advisories/GHSA-6wrg-x3j6-x464https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-121-01.jsonhttps://www.cve.org/CVERecord?id=CVE-2026-43510https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H