Improper Input Validation in .NET Elevates Privileges for Unauthorized Users
CVE-2026-35433

7.3HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
12 May 2026

What is CVE-2026-35433?

The vulnerability in .NET arises due to improper input validation, enabling unauthorized users to elevate their privileges locally. This flaw can be exploited to gain increased access rights within the system, potentially compromising sensitive data or critical functions. It's essential for users and administrators to apply the latest patches and updates to mitigate this flaw.

Affected Version(s)

.NET 10.0 10.0.0 < 10.0.8

.NET 8.0 8.0.0 < 8.0.27

.NET 9.0 9.0.0 < 9.0.16

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.