Impact
The vulnerability is a missing authorization flaw that permits an attacker who already has valid credentials to read sensitive data from the Microsoft Dynamics 365 Business Central environment. The flaw can result in the disclosure of confidential business information over the network, potentially affecting privacy and regulatory compliance. The weakness is identified as CWE‑862, which indicates that role‑based access controls are not correctly enforced, allowing data to be accessed by users who do not have permission to view it.
Affected Systems
Microsoft Dynamics 365 Business Central 2024 Release Wave 2, 2025 Release Wave 1 and Wave 2, and 2026 Release Wave 1 are affected. These versions are specified in the CNA vendor listings and the CPE strings for release waves 1 and 2 of 2024, 2025 and 2026.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as medium severity. The EPSS score indicates that less than 1 % probability of exploitation is expected at present. The flaw is not listed in CISA's KEV catalog, which limits publicly known exploitation data. The likely attack vector is over an authenticated network session, as the attacker needs only authorized credentials to exploit the missing authorization. Without a higher exploitation probability, the risk is mitigated primarily by ensuring that only legitimate users have the necessary privileges, and by applying the vendor's security update.
OpenCVE Enrichment