Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-47303

ASP.NET Core Negotiate authentication: improper parsing allows elevation of privilege

Technology

.NET

CVSS Score

8.8 / 10.0

Affected Versions

Microsoft.AspNetCore.Authentication.Negotiate in .NET 8, 9 and 10 before the July 2026 releases

Upstream Fix

8.0.29; 9.0.18; 10.0.10

Published

July 14, 2026

OSSeva Coverage

Fixed upstream

Description

An elevation of privilege vulnerability exists in the ASP.NET Core Negotiate authentication handler because of improper parsing, classed as authentication bypass by assumed-immutable data. An authenticated attacker can elevate privileges over a network. CVSS is Microsoft's score as the CNA.

Upstream record: NVD · CVE.org

Is your .NET deployment affected?

If you're running Microsoft.AspNetCore.Authentication.Negotiate in .NET 8, 9 and 10 before the July 2026 releases, you need this patch. Book a discovery call to get covered.