CVE-2026-52690
MEDIUMCVSS 5.9/10EPSS 0.35%
Last modified
CVE-2026-52690 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-52690?
Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.
How severe is CVE-2026-52690?
CVE-2026-52690 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2026-52690?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5268An authentication bypass vulnerability exists in the default…9.1
- CVE-2026-52680Apache Kyuubi REST batch multipart upload handling uses the …9.8
- CVE-2026-52684If the auth responds very slowly and the records expire in b…3.7
- CVE-2026-52686The issue is a DNSSEC validation bypass where wildcard expan…3.7
- CVE-2026-52688RRSIGs with too few labels can lead to bypass of DNSSEC wild…7.5
- CVE-2026-5269In Ciena's Navigator Network Control Suite (NCS) and Manage …9.8
- CVE-2026-52692Unauthenticated Sensitive Data Exposure in Affiliates Manage…7.5
- CVE-2026-52693Unauthenticated SQL Injection in eCommerce Product Catalog <…9.3
- CVE-2026-52694Unauthenticated Sensitive Data Exposure in Signature Add-On …7.5
- CVE-2026-52695Unauthenticated Sensitive Data Exposure in ABC Crypto Checko…7.5
- CVE-2026-52696Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 …7.5
- CVE-2026-52697Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.8.5
Are you affected by CVE-2026-52690?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
