{"id":"GHSA-387c-qmrw-59qv","summary":"Duplicate Advisory: Microsoft Security Advisory CVE-2026-26131 – .NET Elevation of Privilege Vulnerability","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-crjq-wm6x-6qx7. This link is maintained to preserve external references.\n\n### Original Description\n\nIncorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.","modified":"2026-03-11T19:02:04.845350Z","published":"2026-03-10T18:31:21Z","withdrawn":"2026-03-11T18:54:29Z","database_specific":{"github_reviewed_at":"2026-03-11T18:54:29Z","nvd_published_at":"2026-03-10T18:18:42Z","cwe_ids":["CWE-276"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26131"},{"type":"PACKAGE","url":"https://github.com/dotnet/dotnet"},{"type":"WEB","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26131"}],"affected":[{"package":{"name":"Microsoft.NetCore.App.Runtime.linux-arm","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.NetCore.App.Runtime.linux-arm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.0.4"}]}],"versions":["10.0.0","10.0.1","10.0.2","10.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-387c-qmrw-59qv/GHSA-387c-qmrw-59qv.json","last_known_affected_version_range":"\u003c= 10.0.3"}},{"package":{"name":"Microsoft.NetCore.App.Runtime.linux-arm64","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.NetCore.App.Runtime.linux-arm64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.0.4"}]}],"versions":["10.0.0","10.0.1","10.0.2","10.0.3"],"database_specific":{"last_known_affected_version_range":"\u003c= 10.0.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-387c-qmrw-59qv/GHSA-387c-qmrw-59qv.json"}},{"package":{"name":"Microsoft.NetCore.App.Runtime.linux-musl-arm","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.NetCore.App.Runtime.linux-musl-arm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.0.4"}]}],"versions":["10.0.0","10.0.1","10.0.2","10.0.3"],"database_specific":{"last_known_affected_version_range":"\u003c= 10.0.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-387c-qmrw-59qv/GHSA-387c-qmrw-59qv.json"}},{"package":{"name":"Microsoft.NetCore.App.Runtime.linux-musl-arm64","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.NetCore.App.Runtime.linux-musl-arm64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.0.4"}]}],"versions":["10.0.0","10.0.1","10.0.2","10.0.3"],"database_specific":{"last_known_affected_version_range":"\u003c= 10.0.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-387c-qmrw-59qv/GHSA-387c-qmrw-59qv.json"}},{"package":{"name":"Microsoft.NetCore.App.Runtime.linux-musl-x64","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.NetCore.App.Runtime.linux-musl-x64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.0.4"}]}],"versions":["10.0.0","10.0.1","10.0.2","10.0.3"],"database_specific":{"last_known_affected_version_range":"\u003c= 10.0.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-387c-qmrw-59qv/GHSA-387c-qmrw-59qv.json"}},{"package":{"name":"Microsoft.NetCore.App.Runtime.linux-x64","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.NetCore.App.Runtime.linux-x64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.0.4"}]}],"versions":["10.0.0","10.0.1","10.0.2","10.0.3"],"database_specific":{"last_known_affected_version_range":"\u003c= 10.0.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-387c-qmrw-59qv/GHSA-387c-qmrw-59qv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}