Description
Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from an origin validation error in the .NET runtime that permits an unauthorized attacker to read sensitive data. An attacker could construct network requests that bypass the reference origin check, causing the application to expose information. The weakness is categorized as CWE‑346, indicating externally controllable input leading to improper validation.

Affected Systems

Affected systems include Microsoft .NET 8.0, .NET 9.0, .NET 10.0 and .NET 11.0, as well as Microsoft Visual Studio 2022 version 17.14 and Visual Studio 2026 version 18.9. The issue applies to the listed releases and their current configurations.

Risk and Exploitability

The CVSS score of 6.5 reflects moderate severity, and the EPSS score is not available, indicating no current data on exploit prevalence. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker to send crafted requests over a network that mistreat the origin header, enabling data disclosure. The risk is moderate, with potential for an attacker to gain access to confidential information if the affected software processes incoming network traffic without proper origin validation.

Generated by OpenCVE AI on September 8, 2026 at 18:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Microsoft security updates that fix the origin validation flaw for all affected .NET runtime versions and Visual Studio releases.
  • Configure strict CORS settings on all services that expose network endpoints, ensuring that only trusted origins are accepted.
  • If the patch cannot be applied immediately, use firewall rules or API gateways to restrict traffic to authorized sources and isolate the vulnerable components from untrusted networks.

Generated by OpenCVE AI on September 8, 2026 at 18:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Visual Studio 2022
Microsoft microsoft Visual Studio 2026
Vendors & Products Microsoft microsoft Visual Studio 2022
Microsoft microsoft Visual Studio 2026

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
Title .NET Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
Weaknesses CWE-346
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .net Microsoft Visual Studio 2022 Microsoft Visual Studio 2026 Visual Studio 2022 Visual Studio 2026
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T20:06:52.403Z

Reserved: 2026-07-01T21:14:44.619Z

Link: CVE-2026-58649

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:17:44.380

Modified: 2026-09-08T20:17:35.987

Link: CVE-2026-58649

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:30:17Z

Weaknesses