Executive brief
A security vulnerability exists in the ASP.NET Core component responsible for handling Windows-based authentication (Negotiate). An attacker with basic network access could exploit this flaw to gain higher-level permissions than they should have, potentially leading to unauthorized access to sensitive data or administrative functions. Organizations using .NET 8, 9, or 10 should update their applications to the latest patched versions to prevent unauthorized privilege escalation.
Technical details
An elevation of privilege vulnerability exists in the Microsoft.AspNetCore.Authentication.Negotiate package due to improper parsing of authentication data. The flaw involves a combination of LDAP injection (CWE-90), authentication bypass via assumed-immutable data (CWE-302), and incorrect authorization (CWE-863). A remote attacker with low privileges can exploit this over the network without user interaction to bypass security checks or escalate their authority within the application. The vulnerability is addressed in versions 8.0.29, 9.0.18, and 10.0.10. Developers must update their NuGet package references and redeploy applications, including self-contained deployments.
Affected products
- Microsoft Microsoft.AspNetCore.Authentication.Negotiate >= 8.0.0, <= 8.0.28; >= 9.0.0, <= 9.0.17; >= 10.0.0, <= 10.0.9
Timeline
- 2026-07-14: disclosed: Initial advisory publication
- 2026-07-21: advisory: GitHub Advisory updated
References
- https://github.com/dotnet/aspnetcore/security/advisories/GHSA-2p3q-h3hg-jcqq
- https://github.com/dotnet/announcements/issues/411
- https://github.com/dotnet/aspnetcore/discussions/67786
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47303
- https://api.github.com/repos/dotnet/aspnetcore/security-advisories/GHSA-2p3q-h3hg-jcqq