CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-40372

CVSS 9.1v3.1pub. 2026-04-21upd. 2026-06-27

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

🤖 AI Analysis
How it works

An attacker can send over the network crafted data or tokens with an incorrect or forged cryptographic signature, which an application based on ASP.NET Core accepts without proper verification. Lack of proper signature integrity control enables bypassing authentication or authorization mechanisms. As a result, an attacker can impersonate a privileged user or gain access to resources they would not normally have access to.

Impact

An attacker without any privileges can remotely obtain elevated access level in the application, leading to violation of confidentiality and integrity of processed data (high impact on C and I according to CVSS).

Mitigation & patch

Security patches available from the manufacturer should be applied in accordance with the references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40372

Who is affected

Microsoft ASP.NET Core — versions indicated in the manufacturer's references (Microsoft Security Response Center)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Microsoft Asp.net Core

    APP
    Microsoft
    10.0.0 – 10.0.7 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-55315CRITICAL9.9PL ✓same product

HTTP Request Smuggling w ASP.NET Core umożliwia ominięcie zabezpieczeń

CVE-2023-38180HIGH7.5⚠ KEVsame product

.NET and Visual Studio Denial of Service Vulnerability

CVE-2026-45591HIGH7.5same product

Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a netwo...

CVE-2026-26130HIGH7.5same product

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny s...

CVE-2025-26682HIGH7.5same product

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny s...