CVE-2026-69806
.NET Elevation of Privilege Vulnerability
Description
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-69806 is a .NET weakness that can let a local attacker increase their permissions on a machine running affected .NET or Visual Studio; small businesses should patch because it can turn a limited foothold into full control of that machine.
In .NET, CVE-2026-69806 is an elevation-of-privilege issue that can be triggered by a local attacker to gain higher permissions on the affected system (CWE-94/CWE-200).
What to do now
- Check which versions of .NET you have installed (/.NET 9.0, 10.0, or 11.0), and whether those versions are below the fixed builds listed below.
- Check whether Microsoft Visual Studio 2022 version 17.14 is installed and confirm whether it’s below 17.14.40.
- Check whether Microsoft Visual Studio 2026 version 18.9 is installed and confirm whether it’s below 18.9.3.
- Upgrade .NET to a fixed version: .NET 10.0 to 10.0.111 or 10.0.400; .NET 11.0 to the RC1 fixed build; .NET 9.0 to 9.0.317.
- Upgrade Visual Studio: Visual Studio 2022 version 17.14 to 17.14.40; Visual Studio 2026 version 18.9 to 18.9.3.
CVSS Vector Breakdown
AV:LAttack VectorAC:HAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-69806 and every CVE in our database. Create a free account — no credit card required.
Create Free Account