Description
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ASP.NET Core is impacted by an authentication bypass that leverages data assumed to be immutable. The flaw enables an authorized attacker to gain higher privileges than originally granted over a network, threatening confidentiality, integrity, and availability of protected resources. This vulnerability is linked to CWE‑302, CWE‑472, CWE‑863, and CWE‑90.

Affected Systems

Microsoft products affected are .NET SDKs 8.0, 9.0, and 10.0, as well as Microsoft Visual Studio 2022 (versions 17.12 and 17.14) and Microsoft Visual Studio 2026 (version 18.7). The updates required to remediate the flaw are applied through Microsoft’s official security update for CVE‑2026‑47303, as listed in the Microsoft Security Response Center. All affected components must be upgraded to the latest available release for respective product lines.

Risk and Exploitability

The CVSS base score of 8.8 signals a high severity risk. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation. The flaw is not listed in the CISA KEV catalog. The description states that authentication bypass via data assumed to be immutable allows an authorized attacker to elevate privileges over a network. This suggests that an attacker who already has authenticated access could potentially exploit the flaw, but the exact mechanics (such as specific requests or required conditions) are not detailed in the available information. Therefore the risk assessment is based solely on the official description and the CVSS metrics.

Generated by OpenCVE AI on July 31, 2026 at 05:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for CVE‑2026‑47303 to .NET SDKs 8.0, 9.0, or 10.0 and to Visual Studio 2022 (17.12/17.14) and Visual Studio 2026 (18.7) upgrades.
  • Upgrade to the latest patched release of the affected .NET and Visual Studio versions if the update is not yet available.
  • Review and enforce identity and authentication mechanisms to guard against unintended elevation of privilege.

Generated by OpenCVE AI on July 31, 2026 at 05:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2p3q-h3hg-jcqq Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability
Ubuntu USN Ubuntu USN USN-8553-1 .NET vulnerabilities
History

Sat, 18 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat hummingbird
Weaknesses CWE-472
CPEs cpe:/a:redhat:hummingbird:1
Vendors & Products Redhat
Redhat hummingbird
References
Metrics threat_severity

None

threat_severity

Important


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Description Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Title ASP.NET Core Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
Weaknesses CWE-302
CWE-863
CWE-90
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .net Visual Studio 2022 Visual Studio 2026
Redhat Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:52:51.774Z

Reserved: 2026-05-18T23:53:33.898Z

Link: CVE-2026-47303

cve-icon Vulnrichment

Updated: 2026-07-14T19:11:27.008Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T18:45:33Z

Links: CVE-2026-47303 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:45:03Z

Weaknesses
  • CWE-302

    Authentication Bypass by Assumed-Immutable Data

  • CWE-472

    External Control of Assumed-Immutable Web Parameter

  • CWE-863

    Incorrect Authorization

  • CWE-90

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')