Junglewise Threat Intelligence

CVE-2026-42898: Microsoft Dynamics 365 code injection

CVE-2026-42898 · Severity: critical · CVSS 9.9 · Published 2026-05-12

Technologies: Microsoft Dynamics 365 (on-premises). Vendors: Microsoft.

Executive brief

Microsoft Dynamics 365 (on-premises) is a business application suite used for managing customer relationships and enterprise resources. A critical vulnerability allows an authorized user to inject and execute malicious code on the server over the network. This could lead to a complete takeover of the system, unauthorized access to sensitive business data, and disruption of corporate operations.

Technical details

A code injection vulnerability (CWE-94) exists in Microsoft Dynamics 365 (on-premises) due to improper control of the generation of code. An attacker with low-privileged credentials can exploit this flaw over a network without user interaction. Successful exploitation allows for arbitrary code execution with a 'Changed' scope (S:C), meaning the attacker can potentially impact components beyond the Dynamics 365 application itself. Microsoft has released security updates to address this issue; administrators should refer to the Microsoft Security Update Guide for specific patch details.

Affected products

  • Microsoft Dynamics 365 (on-premises)

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats