
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26131 is a .NET Elevation of Privilege vulnerability caused by incorrect default permissions (CWE-276) in Microsoft .NET 10.0 Linux runtime packages. It affects .NET versions 10.0.0 through 10.0.3 on Linux platforms (all architectures), and was publicly disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, GitHub Advisory).
The root cause is improper packaging permissions (CWE-276) in the .NET 10.0 Linux runtime packages, where installed file permissions are set in a way that allows unauthorized modification or access by lower-privileged users. An authorized local attacker with low privileges can exploit these incorrect default permissions to escalate their privileges on the affected system. The vulnerability is specific to Linux platforms (including musl-based distributions) across all architectures (x64, arm, arm64), and does not require user interaction to exploit once local access is obtained. The issue was acknowledged and credited to researcher Igor Kovalchuk (GitHub Advisory).
Successful exploitation allows a local low-privileged attacker to escalate privileges to a higher level, potentially achieving system-level access on affected Linux hosts running .NET 10.0.0–10.0.3. This can result in unauthorized access to sensitive data (high confidentiality impact), unauthorized modification of system files or application data (high integrity impact), and potential disruption of services (high availability impact). Self-contained .NET applications deployed on vulnerable runtime versions are also affected and must be recompiled and redeployed (GitHub Advisory, MSRC Advisory).
Microsoft released a patch on March 10, 2026; upgrading to .NET 10.0.4 or later fully remediates the vulnerability. Affected NuGet packages include Microsoft.NetCore.App.Runtime.linux-arm, linux-arm64, linux-musl-arm, linux-musl-arm64, linux-musl-x64, and linux-x64 — all should be updated to version 10.0.4. Developers with self-contained applications targeting affected versions must recompile and redeploy their applications after updating the runtime. As an interim measure, restrict local access to systems running vulnerable .NET versions and apply the principle of least privilege (GitHub Advisory, .NET Dev Blog).
The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security vendors and researchers, including Tenable, Rapid7, Zero Day Initiative, and Sophos, though none highlighted it as a critical priority given the absence of active exploitation (Tenable Blog, ZDI Blog). Community sentiment reflected routine patch urgency, with no notable alarm given the local-only attack vector and lack of public PoC.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."