Executive brief
Microsoft Dynamics 365 (on-premises) is a business application suite used for managing customer relationships and enterprise resources. A security vulnerability in this software allows an existing user with low-level access to gain higher-level administrative permissions. If exploited, an attacker could gain full control over the system, potentially leading to the theft of sensitive customer data or disruption of business operations.
Technical details
A privilege escalation vulnerability exists in Microsoft Dynamics 365 (on-premises) categorized as CWE-280 (Improper Handling of Insufficient Permissions or Privileges). The flaw allows an authenticated attacker with low-privileged access to bypass intended permission checks over a network connection. Successful exploitation enables the attacker to gain high-level privileges (equivalent to administrative access), granting them full confidentiality, integrity, and availability impact over the affected environment. Microsoft has released security updates to address this issue; users should refer to the MSRC update guide for specific patching instructions.
Affected products
- Microsoft Dynamics 365 (on-premises)
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory