CVE-2026-47303
ASP.NET Core Negotiate authentication: improper parsing allows elevation of privilege
Technology
.NET
CVSS Score
8.8 / 10.0
Affected Versions
Microsoft.AspNetCore.Authentication.Negotiate in .NET 8, 9 and 10 before the July 2026 releases
Upstream Fix
8.0.29; 9.0.18; 10.0.10
Published
July 14, 2026
OSSeva Coverage
Fixed upstream
Description
An elevation of privilege vulnerability exists in the ASP.NET Core Negotiate authentication handler because of improper parsing, classed as authentication bypass by assumed-immutable data. An authenticated attacker can elevate privileges over a network. CVSS is Microsoft's score as the CNA.
Is your .NET deployment affected?
If you're running Microsoft.AspNetCore.Authentication.Negotiate in .NET 8, 9 and 10 before the July 2026 releases, you need this patch. Book a discovery call to get covered.