CVE-2026-40417
Microsoft · Published May 12, 2026
7.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability. Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
Affected Products
- Microsoft Dynamics 365 Business Central 2026 Release Wave 1
- Microsoft Dynamics 365 Business Central Release Wave 1 2025
- Microsoft Dynamics 365 Business Central Release Wave 2 2025
- Microsoft Dynamics 365 Business Central 2024 Release Wave 2
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C