Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-47300

ASP.NET Core Negotiate authentication: incorrect validation with LDAP roles allows elevation of privilege

Technology

.NET

CVSS Score

8.8 / 10.0

Affected Versions

Microsoft.AspNetCore.Authentication.Negotiate in .NET 8, 9 and 10 before the July 2026 releases

Upstream Fix

8.0.29; 9.0.18; 10.0.10

Published

July 14, 2026

OSSeva Coverage

Fixed upstream

Description

An elevation of privilege vulnerability exists in the ASP.NET Core Negotiate authentication handler because of improper validation. Microsoft says an application is affected only if it uses Negotiate authentication and retrieves role information from LDAP. CVSS is Microsoft's score as the CNA.

Upstream record: NVD · CVE.org

Is your .NET deployment affected?

If you're running Microsoft.AspNetCore.Authentication.Negotiate in .NET 8, 9 and 10 before the July 2026 releases, you need this patch. Book a discovery call to get covered.