7.8
CVE-2026-40417
- EPSS 0.27%
- Veröffentlicht 12.05.2026 16:58:47
- Zuletzt bearbeitet 10.08.2026 16:19:42
- Erkennungen
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Dynamics 365 Business Central Version 2024 Update release_wave_2
Microsoft ≫ Dynamics 365 Business Central Version 2025 Update release_wave_1
Microsoft ≫ Dynamics 365 Business Central Version 2025 Update release_wave_2
Microsoft ≫ Dynamics 365 Business Central Version 2026 Update release_wave_1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.187 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-1390 Weak Authentication
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40417