CVE-2026-45491: .NET Tampering Vulnerability

Overview

Severity
Medium (CVSS 6.2)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
Category
Tampering
Exploit Status
Not Exploited
Exploitation Likelihood
Unlikely
Patch Tuesday
2026-Jun
Released
2026-06-09

Description

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

Affected Products (10)

Developer Tools

  • .NET 10.0 installed on Windows
  • .NET 10.0 installed on Mac OS
  • .NET 10.0 installed on Linux
  • .NET 8.0
  • .NET 8.0 installed on Windows
  • .NET 8.0 installed on Linux
  • .NET 8.0 installed on Mac OS
  • .NET 9.0 installed on Linux
  • .NET 9.0 installed on Mac OS
  • .NET 9.0 installed on Windows

Security Updates (3)

Acknowledgments

Anonymous, <a href="https://www.linkedin.com/in/ashmitsh4rma/">Ashmit Sharma</a>, <a href="https://www.linkedin.com/in/ashmitsh4rma/">Ashmit Sharma</a>, <a href="https://x.com/ky0tofu">Ky0toFu</a>, <a href="https://x.com/ky0tofu">Ky0toFu</a>, phrolo7a

Revision History

  • 2026-06-09: Information published.