CVE-2026-50650
HIGHCVSS 7.8/10EPSS 0.29%
Last modified
CVE-2026-50650 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | .Net Framework | 4.8 |
| Microsoft | .Net Framework | 4.6.2 |
| Microsoft | .Net Framework | 4.7 |
| Microsoft | .Net Framework | 4.7.1 |
| Microsoft | .Net Framework | 4.7.2 |
| Microsoft | .Net Framework | 3.5 |
| Microsoft | .Net Framework | 4.8.1 |
| Microsoft | .Net | >= 8.0.0, < 8.0.29 |
| Microsoft | .Net | >= 9.0.0, < 9.0.18 |
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50650Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-50650?
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
How severe is CVE-2026-50650?
CVE-2026-50650 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.29% probability of exploitation in the next 30 days.
How do I fix CVE-2026-50650?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-50645There is no restriction on the amount of attachment headers …7.5
- CVE-2026-50646Protection mechanism failure in .NET Framework allows an una…7.8
- CVE-2026-50647Loop with unreachable exit condition ('infinite loop') in Ac…7.5
- CVE-2026-50648Allocation of resources without limits or throttling in .NET…7.5
- CVE-2026-50649Deserialization of untrusted data in .NET allows an unauthor…7.8
- CVE-2026-5065IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains h…8.8
- CVE-2026-50651Allocation of resources without limits or throttling in .NET…7.5
- CVE-2026-50652Deserialization of untrusted data in Azure Active Directory …7.5
- CVE-2026-50653Loop with unreachable exit condition ('infinite loop') in Az…7.5
- CVE-2026-50655Heap-based buffer overflow in Windows Media allows an unauth…7.8
- CVE-2026-50656Microsoft is aware of an elevation of privilege in the Micro…7
- CVE-2026-50657Exposure of private personal information to an unauthorized …5.5
Are you affected by CVE-2026-50650?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
