CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C
- EPSS probability
- 0.56%
- CWE
- CWE-863, CWE-302, CWE-636
- Published
- 2026-07-14
- Last modified
- 2026-09-09
Affected products
- Microsoft .NET 10.0
- Microsoft .NET 8.0
- Microsoft .NET 9.0
- Microsoft Microsoft Visual Studio 2022 version 17.12
- Microsoft Microsoft Visual Studio 2022 version 17.14
- Microsoft Microsoft Visual Studio 2026 version 18.7
Weakness type
Related vulnerabilities
- CVE-2026-87998 — Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
- CVE-2026-87017 — Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
- CVE-2026-87014 — Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
- CVE-2026-46460 — Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and...
- CVE-2026-86773 — Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints
- CVE-2026-86760 — snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag
- CVE-2026-86755 — Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth
- CVE-2026-86754 — Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients