{"id":"CVE-2026-40372","aliases":["BIT-aspnet-core-2026-40372","GHSA-9mv3-2cwr-p262"],"url":"https://o3.security/vulnerability/CVE-2026-40372","summary":"Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege","details":"Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.","published":"2026-04-21T20:16:59.133Z","modified":"2026-07-22T03:57:15.568177Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.DataProtection","fixedVersion":"10.0.7"}],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-40372"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40372.json"},{"type":"ADVISORY","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40372"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2460224"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-22T03:57:15.568177Z"}}