CVE-2026-47300
Microsoft · Published July 14, 2026
8.8
CVSS v3.1
HIGHPatch availableGet patch
Description
ASP.NET Core Elevation of Privilege Vulnerability. Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Affected Products
- .NET 10.0 installed on Linux
- .NET 10.0 installed on Mac OS
- .NET 8.0 installed on Windows
- .NET 8.0 installed on Mac OS
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C