CVE-2026-69806
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Summary
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | .NET 10.0 | 10.0.0 < 10.0.111, 10.0.400 | affected |
| Microsoft | .NET 11.0 | 11.0.0 < 11.0 RC1 | affected |
| Microsoft | .NET 9.0 | 9.0.0 < 9.0.317 | affected |
| Microsoft | Microsoft Visual Studio 2022 version 17.14 | 17.14.0 < 17.14.40 | affected |
| Microsoft | Microsoft Visual Studio 2026 version 18.9 | 18.9.0 < 18.9.3 | affected |
Weaknesses
- CWE-200: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.