CVE-2026-69806
HIGHCVSS 7/10EPSS 1.82%
Last modified
CVE-2026-69806 is a high-severity vulnerability rated 7/10 on the CVSS scale. Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.. EPSS estimates a 1.82% chance of exploitation in the next 30 days.
Description
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | .NET 10.0 | >= 10.0.0, < 10.0.111, 10.0.400 |
| Microsoft | .NET 11.0 | >= 11.0.0, < 11.0 RC1 |
| Microsoft | .NET 9.0 | >= 9.0.0, < 9.0.317 |
| Microsoft | Microsoft Visual Studio 2022 version 17.14 | >= 17.14.0, < 17.14.40 |
| Microsoft | Microsoft Visual Studio 2026 version 18.9 | >= 18.9.0, < 18.9.3 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-69806?
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
How severe is CVE-2026-69806?
CVE-2026-69806 has a CVSS score of 7/10 (HIGH severity). The EPSS model estimates a 1.82% probability of exploitation in the next 30 days.
How do I fix CVE-2026-69806?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-69799Concurrent execution using shared resource with improper syn…7.8
- CVE-2026-6980A vulnerability has been found in Divyanshu-hash GitPilot-MC…7.3
- CVE-2026-69801Heap-based buffer overflow in Windows Audio Service allows a…7.8
- CVE-2026-69803Out-of-bounds read in Windows DHCP Server allows an unauthor…7.5
- CVE-2026-69804Time-of-check time-of-use (toctou) race condition in Microso…7.5
- CVE-2026-69805External control of file name or path in .NET allows an unau…7.5
- CVE-2026-69807Improper limitation of a pathname to a restricted directory …8
- CVE-2026-69808Out-of-bounds read in Windows Win32K allows an authorized at…5.5
- CVE-2026-69809Missing release of memory after effective lifetime in Active…7.5
- CVE-2026-6981A vulnerability was found in IhateCreatingUserNames2 AiraHub…6.3
- CVE-2026-69813Use after free in Windows DNS allows an unauthorized attacke…8.1
- CVE-2026-69814Use after free in Windows Credential Providers allows an aut…7
Are you affected by CVE-2026-69806?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
