Executive brief
Microsoft Dynamics 365 Business Central, an enterprise resource planning (ERP) solution for small and medium-sized businesses, contains a security vulnerability in its authentication mechanism. An attacker who already has basic access to the local system could exploit this flaw to gain higher-level administrative permissions. This could allow an unauthorized user to access sensitive financial data, modify business records, or disrupt critical operations.
Technical details
A privilege escalation vulnerability exists in Microsoft Dynamics 365 Business Central due to weak authentication mechanisms (CWE-1390). The flaw allows a locally authenticated attacker with low-privileged access to bypass certain security checks and elevate their permissions to a higher level. The attack vector is local, meaning the attacker must already have the ability to execute code or log into the affected system. Successful exploitation grants the attacker full control over the application's data and functions (High impact to Confidentiality, Integrity, and Availability). Microsoft has released security updates to address this issue in the affected Release Waves.
Affected products
- Microsoft Dynamics 365 Business Central 2024 Release Wave 2, 2025 Release Wave 1, 2025 Release Wave 2, 2026 Release Wave 1
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Microsoft published the security update guide.