CVE-2026-88131: Microsoft Dataverse Remote Code Execution Vulnerability
Published Oct 8, 2026
·Updated
Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft Dataverse Remote Code Execution Vulnerability
— Microsoft
Affected Software
2 affected components
Microsoft Dataverse
Microsoft Dataverse
Event History
Oct 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
DescriptionSeverity
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this vulnerability?
The vulnerability is exploitable over a network by an unauthorized attacker. No privileges or user interaction are required according to the supplied severity vector.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can allow remote code execution in Microsoft Dataverse. The provided severity vector indicates high impact to confidentiality, integrity, and availability.