CVE-2026-62900
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
- EPSS probability
- 0.55%
- CWE
- CWE-212
- Published
- 2026-08-11
- Last modified
- 2026-09-10
Affected products
- Microsoft .NET 10.0
- Microsoft .NET 8.0
- Microsoft .NET 9.0
- Microsoft Microsoft Visual Studio 2022 version 17.14
- Microsoft Microsoft Visual Studio 2026 version 18.8
Weakness type
Related vulnerabilities
- CVE-2026-86740 — Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains
- CVE-2026-82069 — Improper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster Router
- CVE-2026-53604 — nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
- CVE-2026-78658 — IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability
- CVE-2026-85094 — The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin...
- CVE-2024-5300 — AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd
- CVE-2026-15811 — Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes
- CVE-2026-16104 — Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins