CVE-2026-77903: Microsoft Dataverse Elevation of Privilege Vulnerability
Published Sep 17, 2026
·Updated
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
Other sources
Microsoft Dataverse Elevation of Privilege Vulnerability
— Microsoft
Affected Software
2 affected components
Microsoft Dataverse
Microsoft Dataverse
Event History
Sep 17, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker is unauthorized and does not need prior privileges or user interaction. Exploitation is performed over the network, but the attack complexity is rated high.
2
What is the potential impact if exploitation succeeds?
Successful exploitation allows elevation of privilege and can affect confidentiality, integrity, and availability at a high level. The scope may extend beyond the initially affected security authority.