CVE-2026-40417: Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Other sources
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40417?
The severity of CVE-2026-40417 is rated high with a score of 7.8.
How do I fix CVE-2026-40417?
To fix CVE-2026-40417, ensure your Microsoft Dynamics 365 Business Central is updated to the latest patched version.
What type of vulnerability is CVE-2026-40417?
CVE-2026-40417 is an elevation of privilege vulnerability due to weak authentication in Microsoft Dynamics 365 Business Central.
Who is affected by CVE-2026-40417?
Users of Microsoft Dynamics 365 Business Central, specifically those using versions from 2024 Release Wave 2 onwards, are affected by CVE-2026-40417.
What can an attacker do with CVE-2026-40417?
An authorized attacker can exploit CVE-2026-40417 to elevate privileges locally on the affected systems.