Impact
The vulnerability resides in the .NET framework’s authorization logic, allowing an attacker that can reach the affected service over a network to bypass a security feature that should restrict privileged activity. This flaw is reflected in the attached CWE identifiers, indicating weaknesses in insecure redirect handling, authentication and authorization checks, session handling, and access control. If an attacker successfully exploits the bypass, they can perform actions intended only for authenticated users, compromising the confidentiality, integrity, or availability of the affected application.
Affected Systems
Microsoft .NET 10.0, .NET 8.0, and .NET 9.0 are all impacted, as are Visual Studio 2022 versions 17.12 and 17.14, and Visual Studio 2026 version 18.7. No narrower version scope is specified, so users of any build within these releases should consider themselves vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.2, placing it in the high severity range. The EPSS score is less than 1 %, indicating a low expected exploitation probability at the present time. It is not yet listed in the CISA KEV catalog, meaning there are no confirmed widespread exploits reported. The attack path is inferred to be Network based on the description, with no explicit host or user interaction prerequisites mentioned.
OpenCVE Enrichment
Github GHSA
Ubuntu USN