CVE-2026-26131

Description

Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.045

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2026-26130 are fixed in ASP.NET Core Runtime (10.0) (x64) 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in ASP.NET Core Runtime (10.0) (x86) 10.0.4Windows
Vulnerabilities CVE-2026-26127 are fixed in Dot NET Desktop Runtime (10.0) (x64) 10.0.4Windows
Vulnerabilities CVE-2026-26127 are fixed in Dot NET Desktop Runtime (10.0) (x86) 10.0.4Windows
Vulnerabilities CVE-2026-26127 are fixed in Dot NET Runtime (10.0) (x64) 10.0.4Windows
Vulnerabilities CVE-2026-26127 are fixed in Dot NET Runtime (10.0) (x86) 10.0.4Windows
Vulnerabilities CVE-2026-26127 are fixed in ASP.NET Core Runtime (10.0) (x64) 10.0.4Windows
Vulnerabilities CVE-2026-26127 are fixed in ASP.NET Core Runtime (10.0) (x86) 10.0.4Windows
ASP.NET Core Denial of Service Vulnerability for .NET Hosting (10.0.4) (KB5081276) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x64) (10.0.200) (KB5081276) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x86) (10.0.200) (KB5081276) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x64) (10.0.104) (KB5081276) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x86) (10.0.104) (KB5081276) (CVE-2026-26127)Windows
Vulnerabilities CVE-2026-26131,CVE-2026-26127 are fixed in Nuget-Microsoft.NETCore.App.Runtime.linux-arm 10.0.4Windows
Vulnerabilities CVE-2026-26131,CVE-2026-26127 are fixed in Nuget-Microsoft.NetCore.App.Runtime.linux-musl-arm 10.0.4Windows
Vulnerabilities CVE-2026-26131,CVE-2026-26127 are fixed in Nuget - Microsoft.NETCore.App.Runtime.linux-arm64 10.0.4Windows
Vulnerabilities CVE-2026-26131,CVE-2026-26127 are fixed in Nuget - Microsoft.NETCore.App.Runtime.linux-musl-arm64 10.0.4Windows
Vulnerabilities CVE-2026-26131,CVE-2026-26127 are fixed in Nuget - Microsoft.NETCore.App.Runtime.linux-musl-x64 10.0.4Windows
Vulnerabilities CVE-2026-26131,CVE-2026-26127 are fixed in Nuget - Microsoft.NETCore.App.Runtime.linux-x64 10.0.4Windows
Vulnerabilities CVE-2026-26131,CVE-2026-26127 are fixed in Nuget-Microsoft.NETCore.App.Runtime.linux-arm for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26131,CVE-2026-26127 are fixed in Nuget-Microsoft.NetCore.App.Runtime.linux-musl-arm for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26131,CVE-2026-26127 are fixed in Nuget - Microsoft.NETCore.App.Runtime.linux-arm64 for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26131,CVE-2026-26127 are fixed in Nuget - Microsoft.NETCore.App.Runtime.linux-musl-arm64 for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26131,CVE-2026-26127 are fixed in Nuget - Microsoft.NETCore.App.Runtime.linux-musl-x64 for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26131,CVE-2026-26127 are fixed in Nuget - Microsoft.NETCore.App.Runtime.linux-x64 for Linux 10.0.4Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-43593Update for AspNet Core (x64) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43594Update for AspNet Core (x86) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43595Update for .NET Desktop Runtime (x64) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43596Update for .NET Desktop Runtime (x86) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43597Update for .NET Runtime (x64) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43598Update for .NET Runtime (x86) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43593Update for AspNet Core (x64) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43594Update for AspNet Core (x86) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43592Update for .NET Hosting (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43599Update for .NET SDK (x64) (10.0.200) (KB5081276) (CVE-2026-26127)
PATCH-43600Update for .NET SDK (x86) (10.0.200) (KB5081276) (CVE-2026-26127)
PATCH-43601Update for .NET SDK (x64) (10.0.104) (KB5081276) (CVE-2026-26127)
PATCH-43602Update for .NET SDK (x86) (10.0.104) (KB5081276) (CVE-2026-26127)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234