CVE-2026-26131
C# vulnerability analysis and mitigation

Overview

CVE-2026-26131 is a .NET Elevation of Privilege vulnerability caused by incorrect default permissions (CWE-276) in Microsoft .NET 10.0 Linux runtime packages. It affects .NET versions 10.0.0 through 10.0.3 on Linux platforms (all architectures), and was publicly disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, GitHub Advisory).

Technical details

The root cause is improper packaging permissions (CWE-276) in the .NET 10.0 Linux runtime packages, where installed file permissions are set in a way that allows unauthorized modification or access by lower-privileged users. An authorized local attacker with low privileges can exploit these incorrect default permissions to escalate their privileges on the affected system. The vulnerability is specific to Linux platforms (including musl-based distributions) across all architectures (x64, arm, arm64), and does not require user interaction to exploit once local access is obtained. The issue was acknowledged and credited to researcher Igor Kovalchuk (GitHub Advisory).

Impact

Successful exploitation allows a local low-privileged attacker to escalate privileges to a higher level, potentially achieving system-level access on affected Linux hosts running .NET 10.0.0–10.0.3. This can result in unauthorized access to sensitive data (high confidentiality impact), unauthorized modification of system files or application data (high integrity impact), and potential disruption of services (high availability impact). Self-contained .NET applications deployed on vulnerable runtime versions are also affected and must be recompiled and redeployed (GitHub Advisory, MSRC Advisory).

Mitigation and workarounds

Microsoft released a patch on March 10, 2026; upgrading to .NET 10.0.4 or later fully remediates the vulnerability. Affected NuGet packages include Microsoft.NetCore.App.Runtime.linux-arm, linux-arm64, linux-musl-arm, linux-musl-arm64, linux-musl-x64, and linux-x64 — all should be updated to version 10.0.4. Developers with self-contained applications targeting affected versions must recompile and redeploy their applications after updating the runtime. As an interim measure, restrict local access to systems running vulnerable .NET versions and apply the principle of least privilege (GitHub Advisory, .NET Dev Blog).

Community reactions

The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security vendors and researchers, including Tenable, Rapid7, Zero Day Initiative, and Sophos, though none highlighted it as a critical priority given the absence of active exploitation (Tenable Blog, ZDI Blog). Community sentiment reflected routine patch urgency, with no notable alarm given the local-only attack vector and lack of public PoC.

Additional resources


SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p5rm-jg5c-8c77MEDIUM6.1
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesJul 24, 2026
CVE-2026-62946MEDIUM5.1
  • C# logoC#
  • Magick.NET-Q16-AnyCPU
NoYesJul 24, 2026
CVE-2026-62363MEDIUM5
  • C# logoC#
  • Magick.NET-Q16-HDRI-OpenMP-arm64
NoYesJul 24, 2026
CVE-2026-62343MEDIUM4.7
  • C# logoC#
  • Magick.NET-Q16-OpenMP-arm64
NoYesJul 24, 2026
GHSA-464c-974j-9xm6LOW3.3
  • JavaScript logoJavaScript
  • @aws-cdk/aws-codebuild
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management