CVE-2026-58649: .NET Information Disclosure Vulnerability
.NET Information Disclosure Vulnerability
Other sources
Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.111, 10.0.400 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.120, 9.0.317 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.9.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.0 RC1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.130, 8.0.424 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.40
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker can attempt exploitation over a network without prior privileges, but user interaction is required.
Which environments are identified as affected?
The listed affected software includes Microsoft Visual Studio 2026 and Microsoft .NET 9.0, 10.0, and 11.0 installations across Linux, Windows, and macOS, with .NET 11.0 specifically listed for Windows.