Information Disclosure Vulnerability in Microsoft Dynamics Business Central
CVE-2026-40375

6.5MEDIUM

What is CVE-2026-40375?

A security flaw in Microsoft Dynamics Business Central permits unauthorized disclosure of sensitive information over a network, primarily due to absent authorization checks. This situation potentially allows attackers to access confidential data, highlighting the need for immediate attention and patching to ensure user data confidentiality and integrity.

Affected Version(s)

Microsoft Dynamics 365 Business Central 2024 Release Wave 2 -

Microsoft Dynamics 365 Business Central 2026 Release Wave 1 28.0 < 28.0.50938

Microsoft Dynamics 365 Business Central Release Wave 1 2025 26.0 < 26.0.50788

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.