CVE-2026-40306: DNN has same HostGUID for all new installs
All new installations DNN 10.x.x - 10.2.1 installs, have the same Host GUID. This does not affect upgrades from 9.x.x.
Other sources
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40306?
CVE-2026-40306 is considered a moderate severity vulnerability due to the potential risks associated with identical HostGUIDs for new DNN installations.
How do I fix CVE-2026-40306?
To fix CVE-2026-40306, upgrade your DNN installation to version 10.2.2 or later.
Which versions of DNN are affected by CVE-2026-40306?
CVE-2026-40306 affects all new installations of DNN versions 10.x.x up to 10.2.1.
Does CVE-2026-40306 affect DNN upgrades from earlier versions?
No, CVE-2026-40306 does not affect DNN upgrades from version 9.x.x.
What is the main issue introduced by CVE-2026-40306?
The main issue introduced by CVE-2026-40306 is that all new installations of DNN 10.x.x have the same Host GUID, which could lead to security concerns.