Description
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
Published: 2026-06-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper handling of access control in Microsoft Dynamics 365 on‑premises allows an attacker with existing authorization to raise their privileges across the network. The flaw stems from a missing access control mechanism (CWE‑755) that fails to validate adequate permissions before permitting higher-level actions. Consequently, the attacker can gain elevated access, potentially controlling system functions that should remain restricted, thereby raising confidentiality and integrity risks.

Affected Systems

Microsoft Dynamics 365 (on‑premises) version 9.1 is affected.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score is 0.0063 and the vulnerability is not listed in the CISA KEV catalog, the risk remains significant because the attack vector requires an authorized user with existing access, which is a realistic scenario in many environments. Exploitation would involve the attacker leveraging the application's insufficient permission checks to elevate privileges over the network, resulting in potential system compromise.

Generated by OpenCVE AI on August 12, 2026 at 02:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update for Microsoft Dynamics 365 on‑premises when released
  • Configure least‑privilege settings to limit authorized user permissions
  • Monitor for unapproved privilege changes and review audit logs regularly

Generated by OpenCVE AI on August 12, 2026 at 02:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft dynamics 365 Server
Vendors & Products Microsoft dynamics 365 Server

Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
Title Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft dynamics 365
Weaknesses CWE-280
CPEs cpe:2.3:a:microsoft:dynamics_365:*:*:*:*:on-premises:*:*:*
Vendors & Products Microsoft
Microsoft dynamics 365
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Dynamics 365 Dynamics 365 Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-25T22:43:41.845Z

Reserved: 2026-04-11T23:06:15.615Z

Link: CVE-2026-40371

cve-icon Vulnrichment

Updated: 2026-06-10T10:21:46.217Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T17:17:05.970

Modified: 2026-07-23T08:10:00.137

Link: CVE-2026-40371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T02:15:17Z

Weaknesses
  • CWE-280

    Improper Handling of Insufficient Permissions or Privileges

  • CWE-755

    Improper Handling of Exceptional Conditions