Impact
An attacker can spoof authentication credentials in Microsoft Dataverse, bypassing normal authentication checks and obtaining higher level privileges over a network. This elevation of privilege allows unauthorized actions that could compromise data integrity and confidentiality. The weakness is classified as Improper Restriction of Authentication.
Affected Systems
Microsoft Dataverse instances are affected, with no specific version information provided; any deployment that currently uses Dataverse without the latest update is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9 indicates a severe vulnerability, while the EPSS score of < 1 % suggests a low probability of exploitation at this time and it is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector is network-based spoofing of authentication traffic, requiring the attacker to be able to send crafted requests to the Dataverse service.
OpenCVE Enrichment