Join our Experts on June 24 as they explain how to Detect, Divert, and Deceive AI-Assisted Threats

CVE-2026-40372

Authentication Cookie Forgery in ASP.NET Core Data Protection Can Lead to Privilege Escalation: CVE-2026-40372 Explained

CVSS Gauge
CVSS Needle

Summary

CVE-2026-40372 is a critical ASP.NET Core Data Protection vulnerability caused by improper cryptographic signature verification in Microsoft.AspNetCore.DataProtection versions 10.0.0 through 10.0.6. The flaw allows attackers to forge authentication cookies and protected payloads, potentially enabling privilege escalation and unauthorized access. Microsoft fixed the issue in version 10.0.7, and immediate patching, along with Data Protection key rotation, is strongly recommended. 

Urgent Actions Required

Which Systems Are Vulnerable to CVE-2026-40372?

Technical Overview 

How Does the CVE-2026-40372 Exploit Work?

The attack typically follows these steps:

CVE-2026-40372

What Causes CVE-2026-40372?

Vulnerability Root Cause:   

This vulnerability is caused by improper cryptographic signature verification in Microsoft.AspNetCore.DataProtection versions 10.0.0 – 10.0.6. The managed authenticated encryptor incorrectly validates the HMAC of protected payloads, allowing specially crafted authentication data to bypass integrity checks. As a result, attackers can forge authentication cookies, antiforgery tokens, and other protected payloads that the application may incorrectly trust as legitimate, potentially leading to unauthorized access and privilege escalation. 

How Can You Mitigate CVE-2026-40372? 

If immediate patching is delayed or not possible: 

  • Monitor authentication endpoints for abnormal request patterns and suspicious token activity.
  • Review logs for repeated requests involving authentication cookies, antiforgery tokens, or protected payloads.
  • Rotate the Data Protection key ring to invalidate potentially forged tokens.
  • Audit long-lived artifacts such as refresh tokens, API keys, and password reset links issued during the vulnerable period.
  • Rebuild and redeploy applications after updating affected Data Protection packages or runtimes.

Which Assets and Systems Are at Risk?

Will Patching CVE-2026-40372 Cause Downtime?

Patch application impact: Low. Updating to Microsoft.AspNetCore.DataProtection 10.0.7 typically requires rebuilding and redeploying applications with minimal downtime. Restarting services may be required to load patched components.

Mitigation (if immediate patching is not possible): Monitor for suspicious authentication activity, rotate Data Protection keys, and audit tokens issued during the vulnerable period. Systems remain at risk until the official patch is applied.

How Can You Detect CVE-2026-40372 Exploitation?

Exploitation Signatures:

Look for abnormal request volume against endpoints that process authentication cookies, antiforgery tokens, or protected payloads. Repeated requests with varying cookie or query parameter values may indicate exploitation attempts.

MITRE ATT&CK Mapping:

Indicators of Compromise (IOCs/IOAs):

Behavioral Indicators:

Alerting Strategy:

Remediation & Response

Compliance & Governance Notes

See How Fidelis Deception® Helps Detect and Trap Attackers Early

      • Intelligent decoys, breadcrumbs, and active deception capabilities
      • Real-time visibility into attacker movement across your environment
      • High-fidelity alerts and cyber terrain mapping for faster response
Download the Data Sheet

CVSS Breakdown Table 

MetricValue Description
Base Score9.1Critical severity vulnerability with high security impact
Attack VectorNetwork   Can be exploited remotely over the network
Attack ComplexityLowExploitation does not require complex conditions
Privileges RequiredNoneNo authentication is needed for exploitation
User Interaction NoneExploitation does not require user action
Scope Unchanged The vulnerability impacts the vulnerable application component
Confidentiality Impact HighAttackers may access sensitive protected data
Integrity Impact HighAttackers may forge authentication payloads or modify protected data
Availability ImpactNoneNo direct impact on system availability was reported

Related Readings

One Platform for All Adversaries

See Fidelis in action. Learn how our fast and scalable platforms provide full visibility, deep insights, and rapid response to help security teams across the World protect, detect, respond, and neutralize advanced cyber adversaries.