Description
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
Published: 2026-06-18
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Dynamics 365 suffers an improper access control flaw that permits an authenticated user with limited privileges to gain higher-level permissions across the network, enabling full control of the application and its data. The weakness, identified as CWE-284, allows an attacker to bypass authorization checks and potentially read, modify, or delete sensitive information, compromise system integrity, and disrupt business operations.

Affected Systems

The vulnerability affects Microsoft Dynamics 365. No specific version range is provided, so all installations are potentially vulnerable unless otherwise documented by Microsoft.

Risk and Exploitability

The CVSS score of 9.9 indicates the flaw is extremely severe. Because the EPSS score is not available, the current publicly known likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network-based, requiring the attacker to be authenticated within the system but with insufficient privileges to perform the privileged actions, then leverage the flaw to elevate access. Once escalated, the attacker can exert full control over the application and its underlying data.

Generated by OpenCVE AI on June 18, 2026 at 23:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft patch or update to the latest release as indicated in the Microsoft Security Response Center advisory.
  • Configure and enforce strict role‑based access controls to limit privileges to the minimum required for each user.
  • Monitor authentication and privileged‑action logs for anomalous activity that may indicate exploitation attempts.

Generated by OpenCVE AI on June 18, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 18 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
Title Dynamics 365 Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft dynamics 365
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:dynamics_365:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft dynamics 365
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Dynamics 365
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-18T21:42:40.084Z

Reserved: 2026-05-19T20:12:27.071Z

Link: CVE-2026-47647

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-19T00:00:06Z

Weaknesses