CyberICT

CVE-2026-47300

Microsoft · Published July 14, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

ASP.NET Core Elevation of Privilege Vulnerability. Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

Affected Products

  • .NET 10.0 installed on Linux
  • .NET 10.0 installed on Mac OS
  • .NET 8.0 installed on Windows
  • .NET 8.0 installed on Mac OS

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C