Sep 2026: .NET Elevation of Privilege Vulnerability
CVE-2026-69806 Published on September 8, 2026

.NET Elevation of Privilege Vulnerability
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.

Vendor Advisory NVD

Weakness Types

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2026-69806 has been classified to as an Information Disclosure vulnerability or weakness.

What is a Code Injection Vulnerability?

The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

CVE-2026-69806 has been classified to as a Code Injection vulnerability or weakness.


Products Associated with CVE-2026-69806

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 

Affected Versions

Microsoft .NET 10.0: Microsoft .NET 11.0: Microsoft .NET 9.0: Microsoft Visual Studio 2022 version 17.14: Microsoft Visual Studio 2026 version 18.9: