VDB
GCVE-110-NCSC-2026-235
GCVE-110-NCSC-2026-235
Advisory PublishedCVSS 8.8/10
An incorrect implementation of the authentication algorithm in ASP.NET Core allows an authorized attacker to remotely elevate privileges, posing a significant security risk.
Weaknesses (CWE)
CWE-303Incorrect Implementation of Authentication AlgorithmCWE-770Allocation of Resources Without Limits or ThrottlingCWE-302Authentication Bypass by Assumed-Immutable DataCWE-1287Improper Validation of Specified Type of InputCWE-347Improper Verification of Cryptographic SignatureCWE-59Improper Link Resolution Before File Access ('Link Following')CWE-121Stack-based Buffer OverflowCWE-116Improper Encoding or Escaping of OutputCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-502Deserialization of Untrusted DataCWE-94Improper Control of Generation of Code ('Code Injection')CWE-522Insufficiently Protected CredentialsCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-829Inclusion of Functionality from Untrusted Control Sphere
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | vers:unknown/* | — | — |
Aliases
CVE-2026-41109CVE-2026-45496CVE-2026-45646CVE-2026-47282CVE-2026-47300CVE-2026-47302CVE-2026-47303CVE-2026-47304CVE-2026-47305CVE-2026-50506CVE-2026-50520CVE-2026-50524CVE-2026-50525CVE-2026-50526CVE-2026-50527CVE-2026-50528CVE-2026-50646CVE-2026-50648CVE-2026-50649CVE-2026-50650CVE-2026-50651CVE-2026-50659CVE-2026-56170CVE-2026-57101CVE-2026-57102CVE-2026-57108
Browse GCVE Records
3,045 records in the GCVE database · Updated September 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.