CVE-2026-47300
Analyzed Analyzed - Analysis Complete

Authentication Bypass in ASP.NET Core

Vulnerability report for CVE-2026-47300, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
microsoft .net From 8.0.0 (inc) to 8.0.29 (exc)
microsoft .net From 9.0.0 (inc) to 9.0.18 (exc)
microsoft .net From 10.0.0 (inc) to 10.0.6 (exc)
microsoft visual_studio_2022 From 17.12.0 (inc) to 17.12.22 (exc)
microsoft visual_studio_2022 From 17.14.0 (inc) to 17.14.36 (exc)
microsoft visual_studio_2026 From 18.7.0 (inc) to 18.7.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-303 The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-47300 is a vulnerability in ASP.NET Core related to an incorrect implementation of an authentication algorithm. This flaw allows an attacker who is already authorized (meaning they have some level of access to the system) to elevate their privileges over a network. Essentially, the attacker can gain higher-level permissions than they should have, potentially taking control of affected systems or accessing sensitive data.

The vulnerability is classified as an elevation of privilege (EoP) issue, meaning it does not allow initial access but enables an attacker to escalate their existing access to perform unauthorized actions.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying CVE-2026-47300 on a network or system. Detection may involve checking ASP.NET Core application logs for unusual authentication patterns or unauthorized privilege escalation attempts.

Microsoft may provide detection guidance or tools in their official update guide, which can be referenced for detailed steps.

Impact Analysis

If you are using a system or application built with ASP.NET Core, this vulnerability could have several impacts:

  • An attacker with low-level access could gain administrative or higher privileges, allowing them to take full control of the affected system.
  • The attacker could access, modify, or delete sensitive data stored or processed by the application.
  • The vulnerability could be exploited remotely over a network, increasing the risk of widespread compromise if the application is exposed to the internet.
  • Successful exploitation could lead to service disruptions, data breaches, or further attacks on connected systems.
Compliance Impact

This vulnerability could have significant implications for compliance with various standards and regulations, depending on the nature of the data and systems involved:

  • GDPR (General Data Protection Regulation): If the affected system processes personal data of EU citizens, a breach resulting from this vulnerability could lead to unauthorized access or disclosure of personal data. This may violate GDPR requirements for data protection and could result in fines or legal action if proper safeguards were not in place.
  • HIPAA (Health Insurance Portability and Accountability Act): For organizations handling protected health information (PHI), exploitation of this vulnerability could lead to unauthorized access to PHI, violating HIPAA's Privacy and Security Rules. This could result in penalties and mandatory corrective actions.
  • Other standards like PCI DSS (Payment Card Industry Data Security Standard): If the system processes payment card data, this vulnerability could lead to non-compliance with PCI DSS requirements for securing cardholder data, potentially resulting in fines or loss of payment processing capabilities.

In general, this vulnerability undermines the principle of least privilege and access control, which are fundamental requirements in most compliance frameworks. Organizations may need to demonstrate that they have applied patches or mitigations to avoid compliance violations.

Mitigation Strategies

To mitigate CVE-2026-47300, apply the security updates provided by Microsoft as soon as possible. The vulnerability is addressed in the latest patches for ASP.NET Core.

  • Visit the Microsoft Security Response Center (MSRC) update guide for CVE-2026-47300 to download and install the relevant patches.
  • Ensure all ASP.NET Core applications are updated to the latest secure version.
  • Monitor Microsoft's official communications for additional mitigation steps or workarounds if patches cannot be applied immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47300. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart