CVE-2026-40372
ASP.NET Core Data Protection: forged authentication cookies and payload decryption
Technology
.NET
CVSS Score
9.1 / 10.0
Affected Versions
Microsoft.AspNetCore.DataProtection 10.0.0 to 10.0.6
Upstream Fix
10.0.7
Published
April 21, 2026
OSSeva Coverage
Fixed upstream
Description
A bug in the Microsoft.AspNetCore.DataProtection 10.0.0 to 10.0.6 packages lets an attacker forge authentication cookies to elevate privileges and decrypt some protected payloads. Tokens an attacker induced the application to issue during the vulnerable window, such as session refreshes, API keys or password reset links, stay valid after upgrading to 10.0.7 unless the Data Protection key ring is rotated. CVSS is Microsoft's score as the CNA.
Is your .NET deployment affected?
If you're running Microsoft.AspNetCore.DataProtection 10.0.0 to 10.0.6, you need this patch. Book a discovery call to get covered.