CyberICT

CVE-2026-40417

Microsoft · Published May 12, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability. Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.

Affected Products

  • Microsoft Dynamics 365 Business Central 2026 Release Wave 1
  • Microsoft Dynamics 365 Business Central Release Wave 1 2025
  • Microsoft Dynamics 365 Business Central Release Wave 2 2025
  • Microsoft Dynamics 365 Business Central 2024 Release Wave 2

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C