CVE-2026-47303

Aliases:GHSA-2p3q-h3hg-jcqq
Advisory lineage Upstream: 0 Downstream: 3
PUBLISHED
Published: 14 Jul 2026, 18:45
Last modified:22 Jul 2026, 20:29

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.8 HIGH
v3.1 (cve.org)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Jul 2026, 18:45
Published
Vulnerability first disclosed
22 Jul 2026, 20:29
Last Modified
Vulnerability information updated

Description

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

CVSS Metrics

  • v3.1HIGHScore: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • v3.1HIGHScore: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Techniques & Countermeasures

  • CWE-302Authentication Bypass by Assumed-Immutable Data

    The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.

  • CWE-863Incorrect Authorization

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

  • CWE-90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

    The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.

Affected Systems

  • microsoftmicrosoft visual studio 2022 version 17.12

    ≥ 17.12.0, < 17.12.22

  • microsoftmicrosoft visual studio 2022 version 17.14

    ≥ 17.14.0, < 17.14.36

  • microsoftmicrosoft visual studio 2026 version 18.7

    ≥ 18.0, < 18.7.4

  • microsoft.net 10.0

    ≥ 10.0.0, < 10.0.6 | ≥ 10.0.0, < 10.0.10

  • microsoft.net 8.0

    ≥ 8.0.0, < 8.0.29

  • microsoft.net 9.0

    ≥ 9.0.0, < 9.0.18

  • NuGetMicrosoft.AspNetCore.Authentication.Negotiate

    ≥ 10.0.0, < 10.0.10 | ≥ 9.0.0, < 9.0.18 | ≥ 8.0.0, < 8.0.29

References (6)