Improper Authorization in .NET and Microsoft .NET Framework - CVE-2026-45490
Published: June 9, 2026
Vulnerability identifier: #VU134116
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45490
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to bypass authorization checks.
The vulnerability exists due to insufficient authorization controls in NET SDK. A local user can gain elevated privileges on the target system.
Affected software
.NET
Microsoft .NET Framework
Fedora
dotnet8.0
dotnet9.0
dotnet10.0
Microsoft .NET Framework
Fedora
dotnet8.0
dotnet9.0
dotnet10.0
How to mitigate CVE-2026-45490
Install updates from vendor's website.
.NET - addressed in versions 8.0.28, 9.0.17
Microsoft .NET Framework - update to 10.0.9
dotnet8.0 - addressed in versions 8.0.128-1.fc43, 8.0.128-1.fc44
dotnet9.0 - addressed in versions 9.0.118-1.fc43, 9.0.118-1.fc44
dotnet10.0 - update to 10.0.109-1.fc43
Microsoft .NET Framework - update to 10.0.9
dotnet8.0 - addressed in versions 8.0.128-1.fc43, 8.0.128-1.fc44
dotnet9.0 - addressed in versions 9.0.118-1.fc43, 9.0.118-1.fc44
dotnet10.0 - update to 10.0.109-1.fc43