Improper Access Control in Microsoft Dynamics 365 (On-Premises)
CVE-2026-33103

5.5MEDIUM

What is CVE-2026-33103?

An improper access control vulnerability exists in Microsoft Dynamics 365 (On-Premises), allowing an authorized attacker to access sensitive information locally. Exploiting this flaw could potentially lead to a disclosure of confidential data, emphasizing the importance of implementing strict access controls to protect sensitive information.

Affected Version(s)

Microsoft Dynamics 365 (on-premises) version 9.0 9.0.0 < 9.1.0044.0015

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.