CVE-2026-40417
Microsoft Microsoft Dynamics 365 Business Central 2024 Release Wave 2, Microsoft Dynamics 365 Business Central 2026 Release Wave 1, Microsoft Dynamics 365 Business Central Release Wave 1 2025
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
- CVSS
- 7.8
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.05.13