Junglewise Threat Intelligence

CVE-2026-42833: Microsoft Dynamics 365 code injection

CVE-2026-42833 · Severity: critical · CVSS 9.1 · Published 2026-05-12

Executive brief

Microsoft Dynamics 365 (on-premises) is a business application suite used for customer relationship management and enterprise resource planning. A critical vulnerability allows an authorized user with high-level permissions to inject and execute malicious code on the server. This could lead to a complete takeover of the application environment, unauthorized access to sensitive business data, and disruption of corporate operations.

Technical details

A code injection vulnerability exists in Microsoft Dynamics 365 (on-premises) due to improper control of code generation. An attacker with high-level administrative privileges (PR:H) can exploit this flaw over a network without any user interaction. Successful exploitation allows for arbitrary code execution with the potential to escape the application's security scope (Scope: Changed). The vulnerability is tracked as CWE-94 (Code Injection) and was previously associated with CWE-250 (Execution with Unnecessary Privileges). Microsoft has released security updates to address this issue in version 9.1.45.11 and later.

Affected products

  • Microsoft Dynamics 365 (on-premises) 9.1 up to (excluding) 9.1.45.11

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Initial advisory published by Microsoft
  • 2026-06-01: other: Vulnerability description updated to specify code injection

References

Related threats