CVE-2026-50526

Aliases:GHSA-55jh-fwmh-39m4UBUNTU-CVE-2026-50526BIT-dotnet-2026-50526BIT-dotnet-sdk-2026-50526
Advisory lineage Upstream: 0 Downstream: 18
Analyzed
Published: 14 Jul 2026, 19:29
Last modified:17 Sept 2026, 22:32

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
7 HIGH
v3.1 (cve.org)
EPSS Score
0.23% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Jul 2026, 19:29
Published
Vulnerability first disclosed
17 Sept 2026, 22:32
Last Modified
Vulnerability information updated

Description

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

CVSS Metrics

  • v3.1HIGHScore: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • v3.1HIGHScore: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.23% Percentile: 14%

Techniques & Countermeasures

  • CWE-59Improper Link Resolution Before File Access ('Link Following')

    The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

  • CWE-345Insufficient Verification of Data Authenticity

    The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Systems

  • ubuntudotnet10

    < 10.0.110-10.0.10-0ubuntu1~24.04.1 | < 10.0.110-10.0.10-0ubuntu1~26.04.1

  • ubuntudotnet6

    all

  • ubuntudotnet7

    all

  • ubuntudotnet8

    < 8.0.129-8.0.29-0ubuntu1~22.04.1 | < 8.0.129-8.0.29-0ubuntu1~24.04.1

  • microsoftmicrosoft visual studio 2022 version 17.12

    ≥ 17.12.0, < 17.12.22

  • microsoftmicrosoft visual studio 2022 version 17.14

    ≥ 17.14.0, < 17.14.36

  • microsoftmicrosoft visual studio 2026 version 18.7

    ≥ 18.0, < 18.7.4

  • microsoft.net

    ≥ 8.0.0, < 8.0.29 | ≥ 9.0.0, < 9.0.18 | ≥ 10.0.0, < 10.0.6

  • microsoft.net 10.0

    ≥ 10.0.0, < 10.0.6 | ≥ 10.0.0, < 10.0.10

  • microsoft.net 8.0

    ≥ 8.0.0, < 8.0.29

  • microsoft.net 9.0

    ≥ 9.0.0, < 9.0.18

  • microsoftvisual_studio_2022

    ≥ 17.12.0, < 17.12.22 | ≥ 17.14.0, < 17.14.36

  • microsoftvisual_studio_2026

    ≥ 18.7.0, < 18.7.4

  • NuGetMicrosoft.NET.Build.Containers

    ≥ 10.0.0, < 10.0.10 | ≥ 9.0.0, < 9.0.18 | ≥ 8.0.0, < 8.0.29

References (10)