CVE-2026-66301: Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.
Other sources
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.1.0047.0006
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66301?
The severity of CVE-2026-66301 is medium with a CVSS score of 6.5.
What type of vulnerability is CVE-2026-66301?
CVE-2026-66301 is classified as an information disclosure vulnerability affecting Microsoft Dynamics 365 (On-Premises).
How can I mitigate CVE-2026-66301?
To mitigate CVE-2026-66301, ensure that proper access controls are implemented to restrict unauthorized access to sensitive information.
Who is affected by CVE-2026-66301?
CVE-2026-66301 affects users of Microsoft Dynamics 365 (On-Premises) software.
What can attackers achieve through CVE-2026-66301?
Attackers can exploit CVE-2026-66301 to disclose sensitive information over a network if they have authorized access.