Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9mv3-2cwr-p262 | Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege |
Tue, 28 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft visual Studio 2026
|
|
| CPEs | cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft visual Studio 2026
|
Thu, 23 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. | |
| Title | ASP.NET Core Elevation of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft asp.net Core |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft asp.net Core |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-05-12T17:39:53.725Z
Reserved: 2026-04-11T23:06:15.615Z
Link: CVE-2026-40372
Updated: 2026-04-21T19:40:48.644Z
Status : Analyzed
Published: 2026-04-21T20:16:59.133
Modified: 2026-04-27T19:57:39.360
Link: CVE-2026-40372
OpenCVE Enrichment
Updated: 2026-04-22T06:45:10Z
Github GHSA