VYPR
High severity8.8NVD Advisory· Published Jul 14, 2026· Updated Jul 22, 2026

CVE-2026-47303

CVE-2026-47303

Description

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.AspNetCore.Authentication.NegotiateNuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.AspNetCore.Authentication.NegotiateNuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.AspNetCore.Authentication.NegotiateNuGet
>= 8.0.0, < 8.0.298.0.29

Affected products

47

Patches

Vulnerability mechanics

References

5

News mentions

3