CVE-2026-69805
Awaiting Analysis
Awaiting Analysis - Queue
External Control of File Name in .NET Elevates Privileges
Vulnerability report for CVE-2026-69805, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-08
Last updated on: 2026-09-09
Assigner: Microsoft Corporation
Description
Description
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microsoft | net | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |
| CWE-73 | The product allows user input to control or influence paths or file names that are used in filesystem operations. |
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |