Information disclosure in Visual Studio and .NET for Linux - CVE-2026-69806
Published: September 8, 2026
Vulnerability details
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to exposure of sensitive information to an unauthorized actor in .NET for Linux when local users can access process information through the proc filesystem. A local user can access exposed process information to elevate privileges.
Successful exploitation requires a Linux environment in which users share a process identifier namespace. The attacker can gain the privileges of the user account or service account running the affected process.
Affected software
.NET for Linux
How to mitigate CVE-2026-69806
.NET for Linux - update to 9.0.317