Impact
ASP.NET Core is impacted by an authentication bypass that leverages data assumed to be immutable. The flaw enables an authorized attacker to gain higher privileges than originally granted over a network, threatening confidentiality, integrity, and availability of protected resources. This vulnerability is linked to CWE‑302, CWE‑472, CWE‑863, and CWE‑90.
Affected Systems
Microsoft products affected are .NET SDKs 8.0, 9.0, and 10.0, as well as Microsoft Visual Studio 2022 (versions 17.12 and 17.14) and Microsoft Visual Studio 2026 (version 18.7). The updates required to remediate the flaw are applied through Microsoft’s official security update for CVE‑2026‑47303, as listed in the Microsoft Security Response Center. All affected components must be upgraded to the latest available release for respective product lines.
Risk and Exploitability
The CVSS base score of 8.8 signals a high severity risk. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation. The flaw is not listed in the CISA KEV catalog. The description states that authentication bypass via data assumed to be immutable allows an authorized attacker to elevate privileges over a network. This suggests that an attacker who already has authenticated access could potentially exploit the flaw, but the exact mechanics (such as specific requests or required conditions) are not detailed in the available information. Therefore the risk assessment is based solely on the official description and the CVSS metrics.
OpenCVE Enrichment
Github GHSA
Ubuntu USN