Junglewise Threat Intelligence

CVE-2026-47647: Microsoft Dynamics 365 privilege escalation via improper access control

CVE-2026-47647 · Severity: critical · CVSS 9.9 · Published 2026-06-18

Executive brief

Microsoft Dynamics 365, a suite of enterprise resource planning and customer relationship management applications, contains a critical security flaw. An authorized user with low-level access can exploit improper access controls to gain significantly higher permissions across the platform. This could allow an attacker to access sensitive business data, modify records, or disrupt operations.

Technical details

A privilege escalation vulnerability exists in Microsoft Dynamics 365 due to improper access control (CWE-284). An attacker must be authenticated to the network with low-privileged credentials to exploit this flaw. By sending specially crafted requests to the Dynamics 365 service, the attacker can bypass authorization checks to gain administrative-level access. The vulnerability has a high impact on confidentiality, integrity, and availability, and notably involves a 'Scope' change in the CVSS metric, suggesting the attacker may be able to impact components beyond the initial security scope. Microsoft has addressed this in their security update guide.

Affected products

  • Microsoft Dynamics 365 All versions

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory

References

Related threats