Description
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7 High
EPSS: 1.9% Low
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability in Microsoft .NET involves improper handling of sensitive data and dynamic code generation, exposing confidential information that can be leveraged to elevate privileges locally. This flaw combines the weaknesses identified by CWE-200 and CWE-94, allowing an authorized user to access data that can be used to acquire higher levels of access. As a result, attackers can gain administrative rights on systems where the affected .NET runtime or Visual Studio is installed.

Affected Systems

Microsoft .NET 9.0, 10.0, and 11.0 as well as Microsoft Visual Studio 2022 version 17.14 and Visual Studio 2026 version 18.9 are impacted by this CVE. The affected versions are those explicitly listed in the vendor product references; no further narrowing of sub‑versions is provided.

Risk and Exploitability

The CVSS score of 7 indicates a medium‑to‑high severity, and the EPSS score is 2%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local – it requires an authorized attacker with existing access to the affected environment to exploit the information disclosure and code generation weakness. Once exploited, the attacker can gain full administrative control over the affected system, posing a significant risk to any resources running the impacted .NET components.

Generated by OpenCVE AI on September 9, 2026 at 20:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update released for CVE-2026-69806 to all installed .NET runtimes and Visual Studio editions mentioned.
  • Review and refactor any code that constructs dynamic code or uses format strings to ensure proper sanitization, addressing the CWE‑94 aspect of the flaw.
  • Enforce least privilege for processes and accounts interacting with .NET components and restrict access to sensitive configuration data to mitigate potential privilege escalation.

Generated by OpenCVE AI on September 9, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8740-1 .NET vulnerabilities
History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 00:15:00 +0000


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
Title .NET Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
Weaknesses CWE-200
CWE-94
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .net Visual Studio 2022 Visual Studio 2026
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:39:16.109Z

Reserved: 2026-08-03T22:47:19.710Z

Link: CVE-2026-69806

cve-icon Vulnrichment

Updated: 2026-09-10T18:26:12.135Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-08T18:19:52.190

Modified: 2026-09-25T22:18:08.053

Link: CVE-2026-69806

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-08T17:00:00Z

Links: CVE-2026-69806 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')