
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-69806 is a .NET Elevation of Privilege vulnerability involving exposure of sensitive information that allows a locally authenticated attacker with low privileges to escalate to higher system privileges. It affects .NET 9.0 (before 9.0.317), .NET 10.0 (before 10.0.111 / 10.0.400), .NET 11.0 (before 11.0 RC1), Microsoft Visual Studio 2022 version 17.14 (before 17.14.40), and Microsoft Visual Studio 2026 version 18.9 (before 18.9.3). The vulnerability was disclosed on September 8, 2026, as part of Microsoft's September 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC, Red Hat Bugzilla).
The root cause is that dotnet-watch's AspireServerService component exposes sensitive information through procfs arguments (process filesystem), which can then be leveraged to inject into the /run_session endpoint. This is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-94 (Improper Control of Generation of Code / Code Injection). Exploitation requires local access with low privileges and high attack complexity, meaning the attacker must win a race condition or meet specific environmental preconditions. The vulnerability is Linux-platform-specific based on its reliance on procfs (Red Hat Bugzilla, Microsoft MSRC).
Successful exploitation allows a locally authenticated low-privileged attacker to gain high-level system privileges, with full confidentiality, integrity, and availability impact on the affected host. The attacker can read sensitive process arguments exposed via procfs and inject malicious code into the dotnet-watch /run_session endpoint, potentially achieving arbitrary code execution at elevated privilege levels. This could enable further lateral movement or persistence within the compromised environment (Red Hat Bugzilla, Microsoft MSRC).
As of the disclosure date (September 8, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, reflecting very low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity requirement (e.g., timing or race conditions) further limits opportunistic exploitation (Microsoft MSRC, Red Hat Bugzilla).
dotnet-watch with AspireServerService active (e.g., .NET SDK 9.0.300–9.0.317 or 10.0.100–10.0.111)./proc/<pid>/cmdline or similar procfs entries for the dotnet-watch process to extract sensitive arguments, such as authentication tokens or session identifiers exposed by AspireServerService./run_session endpoint of the AspireServerService./run_session endpoint, exploiting the code injection weakness (CWE-94) to execute arbitrary code or commands at elevated privilege levels, achieving local privilege escalation (Red Hat Bugzilla).dotnet-watch or AspireServerService with elevated privileges; unusual access patterns to /proc/<pid>/cmdline by low-privileged users./run_session endpoint of AspireServerService from unexpected local users or processes; authentication or session token reuse from unexpected sources in application logs.dotnet-watch process owner in sensitive directories; new cron jobs or systemd units created by low-privileged accounts following dotnet-watch activity.dotnet-watch process after /run_session endpoint activity (Red Hat Bugzilla).Microsoft released patches on September 8, 2026. Users should update to the following fixed versions: .NET 9.0 SDK to 9.0.318 or later, .NET 10.0 SDK (1xx channel) to 10.0.112 or later, .NET 10.0 SDK (4xx channel) to 10.0.401 or later, .NET 11.0 to RC1 or later, Visual Studio 2022 version 17.14 to 17.14.40 or later, and Visual Studio 2026 version 18.9 to 18.9.3 or later. No specific configuration-based workaround has been published; upgrading to a patched SDK version is the recommended remediation. Organizations running affected .NET SDK versions on Linux should prioritize patching, especially in multi-user or shared development environments (Microsoft MSRC, Red Hat Bugzilla).
The vulnerability was covered as part of Microsoft's September 2026 Patch Tuesday roundup by BleepingComputer and the Zero Day Initiative (ZDI), which reviewed the broader update release. Microsoft's .NET team published servicing update notes on the official .NET developer blog. No significant independent researcher commentary or social media discussion specific to this CVE has been identified beyond standard Patch Tuesday coverage (BleepingComputer, ZDI Blog, .NET Dev Blog).
Fix availability across major Linux distributions and their releases.
devel
dotnet10: 10.0.112-10.0.12-0ubuntu1
jammy
dotnet6
noble
dotnet10: 10.0.112-10.0.12-0ubuntu1~24.04.1
resolute
dotnet10: 10.0.112-10.0.12-0ubuntu1~26.04.1
RHEL 8
:appstream:dotnet10.0/aspnetcore-runtime-10.0-0:10.0.12-1.el8_10
RHEL 9
:appstream:dotnet10.0/aspnetcore-runtime-10.0-0:10.0.12-1.el9_8
RHEL 10
dotnet10.0/aspnetcore-runtime-10.0-0:10.0.12-1.el10_2
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."