CVE-2026-40372

CRITICAL9.1EPSS 0.02%

ASP.NET Core Elevation of Privilege Vulnerability

Published: 4/23/2026Modified: 4/28/2026
Also known as:GHSA-9mv3-2cwr-p262BIT-aspnet-core-2026-40372

Description

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

References (5)