CVE Vulnerabilities

CVE-2026-50528

Authentication Bypass by Assumed-Immutable Data

Published: Jul 14, 2026 | Modified: Jul 22, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.2 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

Weakness

The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.

Affected Software

NameVendorStart VersionEnd Version
.netMicrosoft8.0.0 (including)8.0.29 (excluding)
.netMicrosoft9.0.0 (including)9.0.18 (excluding)
Red Hat Enterprise Linux 10RedHatdotnet8.0-0:8.0.129-1.el10_2*
Red Hat Enterprise Linux 10RedHatdotnet9.0-0:9.0.119-1.el10_2*
Red Hat Enterprise Linux 10RedHatdotnet10.0-0:10.0.110-1.el10_2*
Red Hat Enterprise Linux 8RedHatdotnet9.0-0:9.0.119-1.el8_10*
Red Hat Enterprise Linux 8RedHatdotnet10.0-0:10.0.110-1.el8_10*
Red Hat Enterprise Linux 8RedHatdotnet8.0-0:8.0.129-1.el8_10*
Red Hat Enterprise Linux 9RedHatdotnet8.0-0:8.0.129-1.el9_8*
Red Hat Enterprise Linux 9RedHatdotnet9.0-0:9.0.119-1.el9_8*
Red Hat Enterprise Linux 9RedHatdotnet10.0-0:10.0.110-1.el9_8*
Red Hat Hardened ImagesRedHatdotnet10-0-main-10.0.109-1.hum1*
Red Hat Hardened ImagesRedHatdotnet9-0-main-9.0.118-1.hum1*
Red Hat Hardened ImagesRedHatdotnet8-0-main-8.0.129-2.1.hum1*
Dotnet10Ubuntudevel*
Dotnet10Ubuntunoble*
Dotnet10Ubunturesolute*
Dotnet7Ubuntujammy*
Dotnet8Ubuntujammy*
Dotnet8Ubuntunoble*

Potential Mitigations

References