Junglewise Threat Intelligence

CVE-2026-40371: Microsoft Dynamics 365 privilege escalation

CVE-2026-40371 · Severity: high · CVSS 8.8 · Published 2026-06-09

Technologies: Microsoft Dynamics 365 (on-premises). Vendors: Microsoft.

Executive brief

Microsoft Dynamics 365 (on-premises) is a business application suite used for managing customer relationships and enterprise resources. A security vulnerability in this software allows an existing user with low-level access to gain higher-level administrative permissions. If exploited, an attacker could gain full control over the system, potentially leading to the theft of sensitive customer data or disruption of business operations.

Technical details

A privilege escalation vulnerability exists in Microsoft Dynamics 365 (on-premises) categorized as CWE-280 (Improper Handling of Insufficient Permissions or Privileges). The flaw allows an authenticated attacker with low-privileged access to bypass intended permission checks over a network connection. Successful exploitation enables the attacker to gain high-level privileges (equivalent to administrative access), granting them full confidentiality, integrity, and availability impact over the affected environment. Microsoft has released security updates to address this issue; users should refer to the MSRC update guide for specific patching instructions.

Affected products

  • Microsoft Dynamics 365 (on-premises)

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats