VDB

GCVE-110-NCSC-2026-235

GCVE-110-NCSC-2026-235
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 14, 2026
An incorrect implementation of the authentication algorithm in ASP.NET Core allows an authorized attacker to remotely elevate privileges, posing a significant security risk.

Weaknesses (CWE)

CWE-303Incorrect Implementation of Authentication AlgorithmCWE-770Allocation of Resources Without Limits or ThrottlingCWE-302Authentication Bypass by Assumed-Immutable DataCWE-1287Improper Validation of Specified Type of InputCWE-347Improper Verification of Cryptographic SignatureCWE-59Improper Link Resolution Before File Access ('Link Following')CWE-121Stack-based Buffer OverflowCWE-116Improper Encoding or Escaping of OutputCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-502Deserialization of Untrusted DataCWE-94Improper Control of Generation of Code ('Code Injection')CWE-522Insufficiently Protected CredentialsCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-829Inclusion of Functionality from Untrusted Control Sphere

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Affected Products

VendorProductVersionsPlatforms
Microsoftvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

3,045 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›