CVE-2026-40372 is a critical privilege escalation vulnerability (CWE-347: Improper Verification of Cryptographic Signature) affecting ASP.NET Core 10.0 prior to version 10.0.7. An unauthenticated remote attacker can exploit the flaw over the network with no user interaction, potentially bypassing authentication or authorization token validation on any exposed ASP.NET Core web service.
The vulnerability carries a CVSS vector of AV:N/AC:L/PR:N/UI:N, reflecting maximum network exploitability with no prerequisites. Although no public exploit code is currently known, the vulnerability is fully confirmed with an official fix available. Organizations running ASP.NET Core 10.0 should upgrade to version 10.0.7 or later immediately.
References:

