Description
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-17
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

An attacker can spoof authentication credentials in Microsoft Dataverse, bypassing normal authentication checks and obtaining higher level privileges over a network. This elevation of privilege allows unauthorized actions that could compromise data integrity and confidentiality. The weakness is classified as Improper Restriction of Authentication.

Affected Systems

Microsoft Dataverse instances are affected, with no specific version information provided; any deployment that currently uses Dataverse without the latest update is potentially vulnerable.

Risk and Exploitability

The CVSS score of 9 indicates a severe vulnerability, while the EPSS score of < 1 % suggests a low probability of exploitation at this time and it is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector is network-based spoofing of authentication traffic, requiring the attacker to be able to send crafted requests to the Dataverse service.

Generated by OpenCVE AI on September 18, 2026 at 23:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the security update for Microsoft Dataverse released by Microsoft, as documented in the official Microsoft Security Response Center advisory.
  • Enforce multi‑factor authentication across all Dataverse access points to ensure identity integrity.
  • Restrict network access to the Dataverse environment, allowing connections only from trusted IP ranges or through VPN gateways.

Generated by OpenCVE AI on September 18, 2026 at 23:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:dataverse:-:*:*:*:*:*:*:*

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Dataverse Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft dataverse
Weaknesses CWE-290
CPEs cpe:2.3:a:microsoft:dataverse:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft dataverse
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Dataverse
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-08T18:12:08.981Z

Reserved: 2026-08-21T17:26:55.613Z

Link: CVE-2026-77903

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:21.931Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T23:18:44.993

Modified: 2026-09-25T20:05:46.080

Link: CVE-2026-77903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:15:17Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing