CVE-2026-69806: .NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
Other sources
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.111, 10.0.400 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.40 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.0 RC1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.9.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.317
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Exploitation requires an authorized attacker with local access and low privileges. The provided vector indicates no user interaction is required, but attack complexity is high.
What impact could successful exploitation have?
A successful attacker could elevate privileges locally. The supplied severity vector rates confidentiality, integrity, and availability impacts as high.
Which listed environments should be reviewed?
Review Linux systems with Microsoft .NET 9.0, 10.0, or 11.0 installed, as well as installations of Microsoft Visual Studio 2022 or Visual Studio 2026.