Executive brief
Microsoft Dataverse is a cloud database service used by organizations to store and manage business data. An attacker can bypass authentication through spoofing to gain unauthorized access and escalate privileges, potentially allowing them to view, modify, or delete sensitive business data without legitimate credentials.
Technical details
An authentication bypass vulnerability in Microsoft Dataverse allows spoofing of credentials to bypass access controls and achieve privilege escalation. The vulnerability is exploitable over the network without requiring pre-existing authentication. A successful exploit grants an attacker unauthorized access to Dataverse resources and elevated permissions within the system.
Affected products
- Microsoft Dataverse
Timeline
- 2026-09-17: disclosed