CVE-2026-26131

HIGH7.8EPSS 0.03%

.NET Elevation of Privilege Vulnerability

Published: 3/11/2026Modified: 4/6/2026
Also known as:GHSA-crjq-wm6x-6qx7BIT-dotnet-2026-26131BIT-dotnet-sdk-2026-26131

Description

Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.

Affected packages (8)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (4)