7

CVE-2026-69806

Medienbericht

.NET Elevation of Privilege Vulnerability

Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ .Net Version >= 9.0.0 < 9.0.20
   Linux ≫ Linux Kernel Version -
Microsoft ≫ .Net Version >= 10.0.0 < 10.0.12
   Linux ≫ Linux Kernel Version -
Microsoft ≫ .Net Version 11.0.0 Update preview1
   Linux ≫ Linux Kernel Version -
Microsoft ≫ .Net Version 11.0.0 Update preview2
   Linux ≫ Linux Kernel Version -
Microsoft ≫ .Net Version 11.0.0 Update preview3
   Linux ≫ Linux Kernel Version -
Microsoft ≫ .Net Version 11.0.0 Update preview4
   Linux ≫ Linux Kernel Version -
Microsoft ≫ .Net Version 11.0.0 Update preview5
   Linux ≫ Linux Kernel Version -
Microsoft ≫ .Net Version 11.0.0 Update preview7
   Linux ≫ Linux Kernel Version -
Microsoft ≫ Visual Studio 2022 Version >= 17.14.0 < 17.14.40
Microsoft ≫ Visual Studio 2026 Version >= 18.9.0 < 18.9.3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.82% 0.775
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69806
Patch
Vendor Advisory