Information Disclosure Vulnerability in .NET Framework by Microsoft
CVE-2026-62902

6.5MEDIUM

What is CVE-2026-62902?

A vulnerability exists in the .NET Framework that enables an unauthorized attacker to exploit functionality stemming from an untrusted control sphere. This scenario may allow the attacker to disclose sensitive information over a network, presenting potential risks for application security. Organizations using affected versions of the .NET Framework should assess their exposure and consider applying recommended patches to mitigate risks associated with this vulnerability.

Affected Version(s)

.NET 8.0 8.0.0 < 8.0.30

.NET 9.0 9.0.0 < 9.0.19

Microsoft Visual Studio 2022 version 17.14 17.14.0 < 17.14.38

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.