
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-69805 is an External Control of File Name or Path vulnerability in Microsoft .NET that allows an unauthenticated network attacker to elevate privileges on affected systems, requiring user interaction to exploit. It affects Microsoft Visual Studio 2022 version 17.14 (prior to 17.14.40), Microsoft Visual Studio 2026 version 18.9 (prior to 18.9.3), and Microsoft.Diagnostics.Runtime version 4.1.740301. The vulnerability was disclosed and patched on September 8, 2026, as part of Microsoft's September 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC, Feedly).
The root cause is classified under CWE-73 (External Control of File Name or Path), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), and CWE-522 (Insufficiently Protected Credentials). The vulnerability exists within .NET's handling of file name or path inputs, where externally supplied values are not sufficiently validated or sanitized, enabling an attacker to manipulate file system calls. Exploitation occurs over the network (AV:N) with high attack complexity (AC:H) and requires user interaction (UI:R), but no prior privileges are needed. Associated attack patterns include path manipulation techniques such as URL encoding bypass (CAPEC-64, CAPEC-72, CAPEC-76) and environment variable subversion (CAPEC-13), as well as dynamic linker hijacking (T1574.006) and PATH environment variable interception (T1574.007) (Microsoft MSRC, Feedly).
Successful exploitation allows an unauthenticated attacker to elevate privileges on the affected system, with high impact to confidentiality, integrity, and availability. An attacker who achieves privilege escalation could access sensitive information, modify system files or configurations, and potentially disrupt service availability. The vulnerability's network attack vector means it can be triggered remotely, increasing the risk of exploitation in environments where affected Visual Studio or .NET Diagnostics Runtime components are exposed (Microsoft MSRC, Feedly).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is 0.0, reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, consistent with the requirement for user interaction (Feedly).
Microsoft released patches on September 8, 2026, as part of the September 2026 Patch Tuesday. Users should update to the following fixed versions: Microsoft Visual Studio 2022 version 17.14.40 or later, Microsoft Visual Studio 2026 version 18.9.3 or later, and Microsoft.Diagnostics.Runtime version 4.1.740301 (patched build). Where immediate patching is not possible, restrict network access to systems running vulnerable versions and implement additional access controls to limit exposure. Monitor for suspicious file path manipulation activity as a compensating control (Microsoft MSRC, .NET Blog).
The vulnerability was covered as part of broader September 2026 Patch Tuesday reporting. BleepingComputer reported on the patch cycle, which addressed 966 flaws and 2 zero-days in total. The Zero Day Initiative (ZDI) published its monthly security update review covering this and other September 2026 patches. Rapid7 also included CVE-2026-69805 in its Patch Tuesday analysis (BleepingComputer, ZDI, Rapid7).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."