Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
An attacker can send over the network crafted data or tokens with an incorrect or forged cryptographic signature, which an application based on ASP.NET Core accepts without proper verification. Lack of proper signature integrity control enables bypassing authentication or authorization mechanisms. As a result, an attacker can impersonate a privileged user or gain access to resources they would not normally have access to.
An attacker without any privileges can remotely obtain elevated access level in the application, leading to violation of confidentiality and integrity of processed data (high impact on C and I according to CVSS).
Security patches available from the manufacturer should be applied in accordance with the references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40372
Microsoft ASP.NET Core — versions indicated in the manufacturer's references (Microsoft Security Response Center)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMicrosoft Asp.net Core
APPMicrosoft10.0.0 – 10.0.7 (excl.)
Related vulnerabilities
HTTP Request Smuggling w ASP.NET Core umożliwia ominięcie zabezpieczeń
.NET and Visual Studio Denial of Service Vulnerability
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a netwo...
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny s...
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny s...