Junglewise Threat Intelligence

CVE-2026-77903: Microsoft Dataverse authentication bypass by spoofing

CVE-2026-77903 · Severity: critical · CVSS 9 · Published 2026-09-17

Vendors: Microsoft.

Executive brief

Microsoft Dataverse is a cloud database service used by organizations to store and manage business data. An attacker can bypass authentication through spoofing to gain unauthorized access and escalate privileges, potentially allowing them to view, modify, or delete sensitive business data without legitimate credentials.

Technical details

An authentication bypass vulnerability in Microsoft Dataverse allows spoofing of credentials to bypass access controls and achieve privilege escalation. The vulnerability is exploitable over the network without requiring pre-existing authentication. A successful exploit grants an attacker unauthorized access to Dataverse resources and elevated permissions within the system.

Affected products

  • Microsoft Dataverse

Timeline

  • 2026-09-17: disclosed

References