CVE-2026-35433

Published: May 19, 2026Last modified: May 19, 2026

Description

Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

Severity score breakdown

ParameterValue
Base score7.3
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux25 LTSdotnet8-runtimeFixed (8.0.27-r0)
Streamdotnet8-runtimeFixed (8.0.27-r0)

References

ON THIS PAGE