CVE-2026-26017Disclosure(coredns.io / coredns)

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch coredns.io coredns systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw. This issue has been patched in version 1.14.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coredns

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-06); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
coredns

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-06: 3Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-06: 3Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 103-0603-1003-1103-12
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-063
Disclosure3
2026-03-101
Disclosure1
2026-03-111
Disclosure1
2026-03-121
Patch1
Full discourse6 posts
  • ThreatCluster@threatcluster
    Patch

    CoreDNS security updates for Fedora and openSUSE fix DNS access control bypass CVE-2026-26017 and DoS flaws CVE-2026-26018, CVE-2025-68156. Patch promptly. #Vulnerabilities https://threatcluster.io/cluster/critical-security-updates-for-coredns-address-multiple-vulne-4f3dc5f5

    Post summary

    The text announces that Fedora and openSUSE CoreDNS updates include patches for three CVEs, fixing an access control bypass and DoS issues.

    0000098
    100 followersView on X
  • Argus Panoptes@Argus_pd
    Disclosure

    new CoreDNS CVE (CVE-2026-26017) — ACL bypass via plugin-chain TOCTOU. DNS is part of your security boundary whether you think about it that way or not. most teams don't.

    Post summary

    A new CoreDNS CVE (CVE‑2026‑26017) is disclosed as an ACL bypass through a plugin‑chain TOCTOU, but no PoC, exploit, or patch information is provided.

    000006
    5 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 CoreDNS, ACL Bypass, #CVE-2026-26017 (High) https://dailycve.com/coredns-acl-bypass-cve-2026-26017-high/

    Post summary

    The tweet announces a high‑severity ACL bypass vulnerability in CoreDNS (CVE‑2026‑26017) and links to a dailycve article for further details.

    0000057
    167 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26017 CoreDNS DNS Access Control Bypass Vulnerability in Versions Prior to 1.14.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26017

    Post summary

    The text announces CoreDNS DNS access control bypass (CVE-2026-26017) affecting versions before 1.14.2 and links to a vulnerability details page.

    0000040
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 CoreDNS, TOCTOU, #CVE-2026-26017 (High) https://dailycve.com/coredns-toctou-cve-2026-26017-high/

    Post summary

    The tweet announces the CoreDNS TOCTOU vulnerability CVE-2026-26017 as a high‑severity flaw, but provides no exploit details or mitigation information.

    0000043
    166 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26017 CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default … https://www.cve.org/CVERecord?id=CVE-2026-26017

    Post summary

    A logical flaw in CoreDNS versions prior to 1.14.2 enables bypass of DNS access controls; the issue is documented as CVE-2026-26017, but no PoC, exploit, or patch details are provided.

    0000082
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcoredns.iocoredns---

Explore more