Executive brief
Microsoft Dynamics 365 (on-premises) is a business application platform used for managing customer relationships and enterprise resources. A security flaw in the on-premises version allows an authorized user on the local system to bypass access controls and view sensitive information they should not be able to see. This could lead to the unauthorized disclosure of internal business data or customer records.
Technical details
An improper access control vulnerability (CWE-284) exists in Microsoft Dynamics 365 (on-premises) version 9.0. The flaw allows an authenticated attacker with local access to the system to bypass security restrictions and gain unauthorized access to sensitive information. The attack vector is local, meaning the attacker must already have credentials and access to the environment where the software is running. Successful exploitation results in a high impact on confidentiality but does not affect system integrity or availability. Microsoft has released updates to address this issue in version 9.1.44.15 and later.
Affected products
- Microsoft Dynamics 365 (on-premises) version 9.0 9.0.0 to 9.1.0044.0015
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory