CVE-2026-55708
published 2026-07-22CVE-2026-55708: In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones…
PriorityP411low3.1CVSS 3.1
AVLACLPRHUIRSUCLILAN
EPSS
0.15%
4.5th percentile
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | >= 1.6.0 < 1.25.2 | 1.25.2 |
| nlnetlabs | unbound | — | — |
| nlnetlabs | unbound | >= 1.6.0 < 1.25.2 | 1.25.2 |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NLnet Labs Unbound up to 1.25.1 Unbound Control view_local_data/view_local_datas privileges management (WID-SEC-2026-2492)
vuldb·2026-09-11·CVSS 3.1
CVE-2026-55708 [LOW] NLnet Labs Unbound up to 1.25.1 Unbound Control view_local_data/view_local_datas privileges management (WID-SEC-2026-2492)
A vulnerability was found in NLnet Labs Unbound up to 1.25.1. It has been declared as problematic. Impacted is the function view_local_data/view_local_datas of the component Unbound Control. The manipulation results in improper privilege management.
This vulnerability is reported as CVE-2026-55708. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view w
ghsa_unreviewed·2026-07-22
CVE-2026-55708 [LOW] CWE-1188 In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view w
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.
Red Hat
unbound: Unbound: Information disclosure due to local policy bypass via unbound-control
vendor_redhat·2026-07-22·CVSS 3.1
CVE-2026-55708 [LOW] CWE-213 unbound: Unbound: Information disclosure due to local policy bypass via unbound-control
unbound: Unbound: Information disclosure due to local policy bypass via unbound-control
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.
A flaw in Unbound's unbound-control utility can omit
No detection rules found.
No public exploits indexed.
2026-07-22
Published