Information disclosure in Visual Studio and .NET for Linux - CVE-2026-69806

 

Information disclosure in Visual Studio and .NET for Linux - CVE-2026-69806

Published: September 8, 2026


Vulnerability identifier: #VU147965
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-69806
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to elevate privileges.

The vulnerability exists due to exposure of sensitive information to an unauthorized actor in .NET for Linux when local users can access process information through the proc filesystem. A local user can access exposed process information to elevate privileges.

Successful exploitation requires a Linux environment in which users share a process identifier namespace. The attacker can gain the privileges of the user account or service account running the affected process.


Affected software

Visual Studio
.NET for Linux

How to mitigate CVE-2026-69806

Install security update from vendor's website.

Visual Studio - update to 17.14.40
.NET for Linux - update to 9.0.317

External References

Related Security Bulletins