cbcvebase.
CVE-2026-40417
published 2026-05-12

CVE-2026-40417: Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.

PriorityP347high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.1th percentile
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.

Affected

7 ranges
VendorProductVersion rangeFixed in
microsoftdynamics_365_business_central
microsoftdynamics_365_business_central
microsoftdynamics_365_business_central
microsoftmicrosoft_dynamics_365_business_central_2024_release_wave_2>= 25.0 < 25.1825.18
microsoftmicrosoft_dynamics_365_business_central_2026_release_wave_1>= 28.0 < 28.128.1
microsoftmicrosoft_dynamics_365_business_central_release_wave_1_2025>= 26.0 < 26.1226.12
microsoftmicrosoft_dynamics_365_business_central_release_wave_2_2025>= 27.0 < 27.627.6
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.