{
  "threat_severity" : "Moderate",
  "public_date" : "2026-07-14T19:29:54Z",
  "bugzilla" : {
    "description" : "dotnet: .NET: Local tampering via improper link resolution",
    "id" : "2500565",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2500565"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.0",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-59",
  "details" : [ "Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.", "A flaw was found in .NET. This vulnerability, stemming from improper link resolution before file access, allows an authorized local attacker to perform tampering. This could lead to unauthorized modification of data or system files." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:41893",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "dotnet8.0-0:8.0.129-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:41895",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "dotnet9.0-0:9.0.119-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:41897",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "dotnet10.0-0:10.0.110-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58566",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "dotnet8.0-0:8.0.130-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58567",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "dotnet9.0-0:9.0.120-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:41899",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "dotnet9.0-0:9.0.119-1.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:41900",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "dotnet10.0-0:10.0.110-1.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:41901",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "dotnet8.0-0:8.0.129-1.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:41894",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "dotnet8.0-0:8.0.129-1.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:41896",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "dotnet9.0-0:9.0.119-1.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:41898",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "dotnet10.0-0:10.0.110-1.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58568",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "dotnet8.0-0:8.0.130-1.el9_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58569",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "dotnet8.0-0:8.0.130-1.el9_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58570",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "dotnet9.0-0:9.0.120-1.el9_6"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-06-17T00:00:00Z",
    "advisory" : "RHSA-2026:26638",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "dotnet10-0-main-10.0.109-1.hum1",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-06-19T00:00:00Z",
    "advisory" : "RHSA-2026:27171",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "dotnet9-0-main-9.0.118-1.hum1",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:42145",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "dotnet8-0-main-8.0.129-2.1.hum1",
    "impact" : "moderate"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenShift Dev Spaces",
    "fix_state" : "Not affected",
    "package_name" : "devspaces/udi-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-50526\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50526\nhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50526" ],
  "name" : "CVE-2026-50526",
  "csaw" : false
}