Description
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
Published: 2026-03-10
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

The vulnerability is an improper default permission configuration in the Microsoft .NET 10.0 runtime that allows an attacker who already has some level of authorized access on a local machine to gain elevated privileges. This weakness, identified as CWE-276, can enable unauthorized code execution or modification of system resources by granting higher privileges than intended. The CVSS score of 7.8 indicates that the potential impact is significant, as the attacker could gain control over system files, alter application behavior, or compromise other users on the machine, leading to integrity and confidentiality loss.

Affected Systems

Affected products are Microsoft's .NET 10.0 runtime. No specific version ranges were provided in the data, so all installations of .NET 10.0 are considered potentially at risk until further details are released. The vendor’s CNA notes list Microsoft as the only vendor with this vulnerability.

Risk and Exploitability

The EPSS score of less than 1% suggests a low probability of exploitation in the wild at this time, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Nevertheless, the CVSS severity of 7.8 raises concern for local high‑privilege attackers. The likely attack vector is local, requiring some level of authorized access (e.g., a standard user or a compromised account). An attacker could exploit this weakness by leveraging the improperly set permissions to promote an application or service to higher privileges, thereby compromising system integrity and confidentiality. Due to the low EPSS and lack of known exploitation, monitoring and timely patching are the recommended risk mitigation strategies.

Generated by OpenCVE AI on March 16, 2026 at 23:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply the latest Microsoft .NET security patch or update, as the vendor issues security updates for this flaw.
  • If a patch is not immediately available, restrict the permissions on the .NET runtime files to the minimum necessary for operation, or disable services that expose the vulnerable components.
  • Monitor the Microsoft Security Response Center and other vendor advisories for any new updates or workarounds related to CVE‑2026‑26131.

Generated by OpenCVE AI on March 16, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-crjq-wm6x-6qx7 .NET Elevation of Privilege Vulnerability
History

Fri, 13 Mar 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 11 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
Description Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
Title .NET Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft .net
Weaknesses CWE-276
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-03-27T22:32:59.237Z

Reserved: 2026-02-11T16:24:51.132Z

Link: CVE-2026-26131

cve-icon Vulnrichment

Updated: 2026-03-11T13:02:09.794Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-10T18:18:42.393

Modified: 2026-03-11T13:53:20.707

Link: CVE-2026-26131

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-03-10T17:05:09Z

Links: CVE-2026-26131 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-03-20T14:34:15Z

Weaknesses