Impact
The flaw stems from an incorrect implementation of the authentication algorithm in ASP.NET Core, allowing an attacker who already has authorized access to raise their privileges across the network. This produces an elevation of privilege condition. The weakness is classified as CWE-303, an authentication bypass vulnerability.
Affected Systems
Microsoft .NET 10.0, 9.0 and 8.0, as well as Microsoft Visual Studio 2022 versions 17.12 and 17.14, and Microsoft Visual Studio 2026 version 18.7, should be checked against the vendor’s advisory for the applicable patches.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered High severity. The EPSS score of less than 1% indicates a low probability of exploitation at present, and the issue is not listed in the CISA KEV catalog. Likely attack scenarios involve an attacker who has legitimate credentials targeting a networked ASP.NET Core application; exploiting the faulty algorithm can elevate privileges without additional access rights.
OpenCVE Enrichment
Github GHSA
Ubuntu USN