CVE-2026-40371

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:dynamics_365:*:*:*:*:on-premises:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Manejo inadecuado de permisos o privilegios insuficientes en Microsoft Dynamics 365 (local) permite a un atacante autorizado elevar privilegios a través de una red.

17 Jun 2026, 14:53

Type Values Removed Values Added
CWE CWE-755
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371 - Vendor Advisory
First Time Microsoft dynamics 365
Microsoft
CPE cpe:2.3:a:microsoft:dynamics_365:*:*:*:*:on-premises:*:*:*

09 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 17:17

Updated : 2026-07-23 08:10


NVD link : CVE-2026-40371

Mitre link : CVE-2026-40371

CVE.ORG link : CVE-2026-40371


JSON object : View

Products Affected

microsoft

  • dynamics_365
CWE
CWE-280

Improper Handling of Insufficient Permissions or Privileges

CWE-755

Improper Handling of Exceptional Conditions