Origin validation error in Microsoft products - CVE-2026-58649

 

Origin validation error in Microsoft products - CVE-2026-58649

Published: September 8, 2026


Vulnerability identifier: #VU147478
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58649
CWE-ID: CWE-346
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an origin validation error in .NET when validating origins. A remote attacker can exploit the vulnerability to disclose sensitive information.

User interaction is required. Successful exploitation could expose developer-time hot reload data, including application metadata, intermediate language updates, debugging information, method names, string literals, and file paths.


Affected software

.NET
Visual Studio
.NET for macOS
.NET for Linux
Microsoft .NET Framework

How to mitigate CVE-2026-58649

Install security update from vendor's website.

.NET - addressed in versions 8.0.130, 8.0.424, 9.0.120, 9.0.317
Visual Studio - update to 17.14.40
.NET for macOS - addressed in versions 8.0.130, 8.0.424, 9.0.120, 9.0.317
.NET for Linux - addressed in versions 8.0.130, 8.0.424, 9.0.120, 9.0.317
Microsoft .NET Framework - update to 10.0.111, 10.0.400

External References

Related Security Bulletins