Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 12 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. | |
| Title | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft dynamics 365 Business Central 2024 Microsoft dynamics 365 Business Central 2025 Microsoft dynamics 365 Business Central 2026 |
|
| Weaknesses | CWE-1390 | |
| CPEs | cpe:2.3:a:microsoft:dynamics_365_business_central_2024:*:release_wave_2:*:*:*:*:*:* cpe:2.3:a:microsoft:dynamics_365_business_central_2025:*:release_wave_1:*:*:*:*:*:* cpe:2.3:a:microsoft:dynamics_365_business_central_2025:*:release_wave_2:*:*:*:*:*:* cpe:2.3:a:microsoft:dynamics_365_business_central_2026:*:release_wave_1:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft dynamics 365 Business Central 2024 Microsoft dynamics 365 Business Central 2025 Microsoft dynamics 365 Business Central 2026 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-05-12T17:53:46.693Z
Reserved: 2026-04-13T00:27:50.798Z
Link: CVE-2026-40417
No data.
Status : Received
Published: 2026-05-12T18:17:19.817
Modified: 2026-05-12T18:17:19.817
Link: CVE-2026-40417
No data.
OpenCVE Enrichment
Updated: 2026-05-12T20:15:24Z
Weaknesses