CVE-2026-62902
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
- EPSS probability
- 0.78%
- CWE
- CWE-829, CWE-693, CWE-918
- Published
- 2026-08-11
- Last modified
- 2026-09-16
Affected products
- Microsoft .NET 10.0
- Microsoft .NET 8.0
- Microsoft .NET 9.0
- Microsoft Microsoft Visual Studio 2022 version 17.14
- Microsoft Microsoft Visual Studio 2026 version 18.8
Weakness type
Related vulnerabilities
- CVE-2026-0770 — Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
- CVE-2025-32463 — Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
- CVE-2025-34074 — Lucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File Write
- CVE-2024-38476 — Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect
- CVE-2026-27941 — OpenLIT Vulnerable to Remote Code Execution and Secret Exposure via Misuse of `pull_request_target` in GitHub Actions Workflows
- CVE-2026-1699 — In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_tar
- CVE-2025-34060 — Monero Forum Remote Code Execution via Arbitrary File Read and Cookie Forgery
- CVE-2025-66022 — FACTION Unauthenticated Custom Extension Upload leads to RCE