CVE-2026-62902: .NET Information Disclosure Vulnerability
.NET Information Disclosure Vulnerability
Other sources
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.30Patch KB5122104 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.11Patch KB5122106 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.8.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.19Patch KB5122105 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.38
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62902?
CVE-2026-62902 has a medium severity rating of 6.5.
What types of systems are affected by CVE-2026-62902?
CVE-2026-62902 affects Microsoft .NET 8.0, 9.0, and 10.0 on Windows, Mac OS, and Linux, as well as Microsoft Visual Studio 2022 and 2026.
How do I fix CVE-2026-62902?
To mitigate CVE-2026-62902, update your affected Microsoft .NET and Visual Studio installations to the latest versions.
What is the impact of CVE-2026-62902?
CVE-2026-62902 allows unauthorized attackers to disclose sensitive information over a network due to an information disclosure vulnerability.
Is CVE-2026-62902 exploitable remotely?
Yes, CVE-2026-62902 can be exploited remotely due to its nature as an information disclosure vulnerability.