---
id: CVE-2026-43510
title: manage.get.gov is the .gov TLD registrar maintained by CISA
summary: >-
  manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov
  allows an organization administrator to assign domain manager privileges for
  domains not already in another organization. Fixed in 1.176.0 on or around
  2026-04-30.
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-266
published: '2026-05-07'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-43510'
references:
  - url: 'https://github.com/cisagov/manage.get.gov/issues/4858'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://github.com/cisagov/manage.get.gov/pull/4900'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://github.com/cisagov/manage.get.gov/releases/tag/v1.176.0'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://github.com/cisagov/manage.get.gov/security/advisories/GHSA-6wrg-x3j6-x464
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-121-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-43510'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
epss: 0.00398
epssPercentile: 0.33831
ingestedAt: '2026-06-26T16:43:13.640Z'
---

## Overview

manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
