CVE-2026-47300
ASP.NET Core Negotiate authentication: incorrect validation with LDAP roles allows elevation of privilege
Technology
.NET
CVSS Score
8.8 / 10.0
Affected Versions
Microsoft.AspNetCore.Authentication.Negotiate in .NET 8, 9 and 10 before the July 2026 releases
Upstream Fix
8.0.29; 9.0.18; 10.0.10
Published
July 14, 2026
OSSeva Coverage
Fixed upstream
Description
An elevation of privilege vulnerability exists in the ASP.NET Core Negotiate authentication handler because of improper validation. Microsoft says an application is affected only if it uses Negotiate authentication and retrieves role information from LDAP. CVSS is Microsoft's score as the CNA.
Is your .NET deployment affected?
If you're running Microsoft.AspNetCore.Authentication.Negotiate in .NET 8, 9 and 10 before the July 2026 releases, you need this patch. Book a discovery call to get covered.