CVE-2026-69806
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
CVSS
7.0
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-94 · CWE-200
Not enough EPSS history yet.
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-866725.3 MED—
———A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.3hCVE-2026-784638.8 HIG—
———Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.3hCVE-2026-779088.8 HIG—
———Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.3hCVE-2026-761918.2 HIG—
———Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.3hCVE-2026-698625.5 MED—
———Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally.3hCVE-2026-698057.5 HIG—
———External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.3h