Junglewise Threat Intelligence

CVE-2026-33821: Microsoft Dynamics 365 Customer Insights privilege escalation

CVE-2026-33821 · Severity: high · CVSS 7.7 · Published 2026-05-12

Vendors: Microsoft.

Executive brief

Microsoft Dynamics 365 Customer Insights, a platform used by businesses to manage and analyze customer data, contains a security vulnerability that allows an authorized user to gain higher-level permissions than they should have. An attacker with basic access to the system could exploit this flaw to perform administrative actions or modify data they are not authorized to change. This could lead to unauthorized configuration changes or data integrity issues within the customer relationship management environment.

Technical details

A privilege escalation vulnerability (CWE-269) exists in Microsoft Dynamics 365 Customer Insights due to improper privilege management. An attacker must be authenticated to the network with low-privileged user permissions to exploit this flaw. By sending specially crafted requests to the service, the attacker can elevate their privileges, potentially gaining the ability to modify system settings or data (Integrity: High). The vulnerability has a Scope change (S:C) according to the CVSS metric, indicating the impact may extend beyond the immediate Customer Insights component. As this is an exclusively hosted service, Microsoft typically manages the deployment of fixes directly to the cloud environment.

Affected products

  • Microsoft Dynamics 365 Customer Insights

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Microsoft and NVD.
  • 2026-05-12: advisory

References