CyberICT

CVE-2026-40375

Microsoft · Published August 11, 2026

CVSS v3.1

MEDIUM
Patch availableGet patch

Description

Microsoft Dynamics Business Central Information Disclosure Vulnerability. Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

Affected Products

  • Microsoft Dynamics 365 Business Central 2024 Release Wave 2
  • Microsoft Dynamics 365 Business Central Release Wave 1 2025
  • Microsoft Dynamics 365 Business Central 2026 Release Wave 1
  • Microsoft Dynamics 365 Business Central Release Wave 2 2025

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C