CVE-2026-43510: CISA manage.get.gov insecure portfolio administrative privileges
manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
manage.get.govto a version that resolves this vulnerability.Fixed in 1.176.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43510?
CVE-2026-43510 has a moderate severity level due to its potential to assign administrative privileges improperly.
How do I fix CVE-2026-43510?
To fix CVE-2026-43510, upgrade to version 1.176.0 or later of CISA manage.get.gov.
What is the impact of CVE-2026-43510?
The impact of CVE-2026-43510 includes unauthorized management of domain privileges which can lead to security breaches.
Which software is affected by CVE-2026-43510?
CVE-2026-43510 affects CISA manage.get.gov versions prior to 1.176.0.
When was CVE-2026-43510 disclosed?
CVE-2026-43510 was disclosed prior to its fix in version 1.176.0 scheduled for around April 2026.