CyberRota Analysis
AI-GeneratedA vulnerability exists in DNSSEC implementations that allows for a bypass of signature validation for wildcard expansion proofs, specifically when the wildcard answer is a CNAME or DNAME record. This could potentially lead to unauthorized DNS responses, compromising the integrity of DNS queries. Organizations relying on DNSSEC for secure domain name resolution should prioritize addressing this issue to mitigate risks associated with DNS spoofing and related attacks.
CVE
CVE-2026-52686
Severity
LOW
CVSS
3.7
EPSS
0.11%
Original NVD Description
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.