Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-40372

ASP.NET Core Data Protection: forged authentication cookies and payload decryption

Technology

.NET

CVSS Score

9.1 / 10.0

Affected Versions

Microsoft.AspNetCore.DataProtection 10.0.0 to 10.0.6

Upstream Fix

10.0.7

Published

April 21, 2026

OSSeva Coverage

Fixed upstream

Description

A bug in the Microsoft.AspNetCore.DataProtection 10.0.0 to 10.0.6 packages lets an attacker forge authentication cookies to elevate privileges and decrypt some protected payloads. Tokens an attacker induced the application to issue during the vulnerable window, such as session refreshes, API keys or password reset links, stay valid after upgrading to 10.0.7 unless the Data Protection key ring is rotated. CVSS is Microsoft's score as the CNA.

Upstream record: NVD · CVE.org

Is your .NET deployment affected?

If you're running Microsoft.AspNetCore.DataProtection 10.0.0 to 10.0.6, you need this patch. Book a discovery call to get covered.