CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-40372

Critical · CVSS 9.1

ASP.NET Core — Improper verification of cryptographic signature leading to privilege escalation

CVSS
9.1
nvd
EPSS
KEV
No
Class
other
CWE-347, CWE-347

Description

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

Search profile — drives PoC discovery

Symbols CryptographicExceptionVerifySignatureSignedXmlDataProtectionIDataProtectorValidateTokenJwtSecurityTokenHandlerSignatureValidatorTokenValidationParametersAuthenticationMiddleware
Keywords CVE-2026-40372ASP.NET Corecryptographic signature bypassprivilege escalationCWE-347signature verificationASP.NET Core authentication bypassdotnet signature spoofingMSRC CVE-2026-40372
Versions: <UNKNOWN>

References

Status: enriched · ingested 2026-06-27T06:00:38.000Z · profiled 2026-07-01T06:30:14.000Z