Description
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability stems from inclusion of code originating in an untrusted control sphere within the .NET framework, enabling an unauthorized attacker to read sensitive information across a network. The affected software exposes data that should remain internal, leading to potential breach of confidentiality. No higher‑level exploitation such as code execution is reported, but the exposure of domain or application data can aid further attacks. This issue represents CWE‑693, CWE‑829, and CWE‑918 weaknesses.

Affected Systems

Microsoft .NET 10.0, Microsoft .NET 8.0, Microsoft .NET 9.0, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2026 version 18.8 are impacted; specific version separators are not provided.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to target the affected runtime or development tools over a network; the exact method is inferred from the description about an information disclosure over a network, but no precise exploit vector is detailed in the data.

Generated by OpenCVE AI on August 12, 2026 at 16:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft .NET and Visual Studio to the most recent patched releases.
  • Limit the network traffic that applications built on these platforms can send or receive to only trusted endpoints.
  • Enable monitoring for anomalous data exfiltration attempts and apply network segmentation to isolate critical services.

Generated by OpenCVE AI on August 12, 2026 at 16:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9mrh-pw7c-9mqm Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
History

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Visual Studio 2022
Microsoft microsoft Visual Studio 2026
Vendors & Products Microsoft microsoft Visual Studio 2022
Microsoft microsoft Visual Studio 2026

Fri, 14 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows
CPEs cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft windows

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
Title .NET Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
Weaknesses CWE-693
CWE-829
CWE-918
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .net Microsoft Visual Studio 2022 Microsoft Visual Studio 2026 Visual Studio 2022 Visual Studio 2026 Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:26.754Z

Reserved: 2026-07-14T21:25:21.035Z

Link: CVE-2026-62902

cve-icon Vulnrichment

Updated: 2026-08-12T13:29:50.222Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:44.503

Modified: 2026-08-14T13:52:51.360

Link: CVE-2026-62902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:15:03Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure

  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere

  • CWE-918

    Server-Side Request Forgery (SSRF)