Junglewise Threat Intelligence

CVE-2026-66301: Microsoft Dynamics 365 sensitive information disclosure

CVE-2026-66301 · Severity: medium · CVSS 6.5 · Published 2026-08-11

Executive brief

Microsoft Dynamics 365 (on-premises) is an enterprise resource planning system that manages critical business data including customer information, financial records, and operational data. A vulnerability in this system allows an authorized user to disclose sensitive information over the network to unauthorized parties, potentially exposing confidential business and customer data.

Technical details

This vulnerability is an information disclosure flaw in Microsoft Dynamics 365 (on-premises) that allows an authenticated attacker with authorized access to extract sensitive data and transmit it over the network. The attack requires the attacker to already have valid credentials and authorized access to the system. By exploiting this vulnerability, an attacker can bypass data confidentiality protections and exfiltrate sensitive business information. A patch is expected to be available through Microsoft's standard security update process.

Affected products

  • Microsoft Dynamics 365 on-premises

Timeline

  • 2026-08-11: disclosed

References

Related threats