Executive brief
.NET is a widely-used development framework used to build web applications, services, and enterprise software. An origin validation error allows an attacker to bypass security controls and access sensitive information through the network without authentication. This could result in the exposure of customer data, credentials, or other confidential information.
Technical details
The vulnerability is an origin validation error in Microsoft .NET that permits information disclosure over a network. The flaw occurs in origin validation logic, which is responsible for verifying that requests originate from trusted sources. An unauthenticated attacker with network access can exploit this weakness to bypass the origin check and retrieve sensitive information from affected applications. The attack vector is network-based and requires no authentication, though the exact preconditions and exploitable component are not fully detailed in the available references.
Affected products
- Microsoft .NET
Timeline
- 2026-09-08: disclosed