CVE-2026-40306 affects DNN (DotNetNuke), an open-source web content management platform, where all new installations of versions 10.0.0 through 10.2.1 are provisioned with an identical Host GUID, creating a shared cryptographic identifier across deployments. This vulnerability does not impact users upgrading from version 9.x.x, and the issue was remediated in version 10.2.2. The duplicate GUID could potentially allow attackers with access to one installation to compromise others if exploited in conjunction with other attack methods, though the exact attack surface is limited by the need for additional vulnerabilities or misconfigurations. There is no evidence of active exploitation in the wild, with no public exploit code available and minimal community attention indicated by the inactive Hot List status and near-zero EPSS score of 0.00055. Organizations running DNN 10.0.0 through 10.2.1 should prioritize upgrading to version 10.2.2 to eliminate this configuration-based weakness, particularly if their installations are internet-facing or accessible to untrusted users.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.2.2CPE matchmatch criteria | cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.