Microsoft Dataverse
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Dataverse.
Recent Microsoft Dataverse Security Advisories
| Advisory | Title | Published |
|---|---|---|
| CVE-2026-77903 | CVE-2026-77903 Microsoft Dataverse Elevation of Privilege Vulnerability | September 17, 2026 |
| CVE-2025-29826 | CVE-2025-29826 Microsoft Dataverse Elevation of Privilege Vulnerability | May 13, 2025 |
| CVE-2025-47732 | CVE-2025-47732 Microsoft Dataverse Remote Code Execution Vulnerability | May 9, 2025 |
| CVE-2025-24053 | CVE-2025-24053 Microsoft Dataverse Elevation of Privilege Vulnerability | March 13, 2025 |
| CVE-2024-38139 | CVE-2024-38139 Microsoft Dataverse Elevation of Privilege Vulnerability | October 15, 2024 |
| CVE-2024-35260 | CVE-2024-35260 Microsoft Dataverse Remote Code Execution Vulnerability | July 9, 2024 |
By the Year
In 2026 there have been 1 vulnerability in Microsoft Dataverse with an average score of 9.0 out of ten. Last year, in 2025 Dataverse had 4 security vulnerabilities published. Right now, Dataverse is on track to have less security vulnerabilities in 2026 than it did last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.03.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 9.00 |
| 2025 | 4 | 7.98 |
| 2024 | 2 | 8.35 |
It may take a day or so for new Dataverse vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Dataverse Security Vulnerabilities
Sep 2026: Microsoft Dataverse Elevation of Privilege Vulnerability
CVE-2026-77903
9 - Critical
- September 17, 2026
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
Authentication Bypass by Spoofing
May 2025: Microsoft Dataverse Elevation of Privilege Vulnerability
CVE-2025-29826
7.3 - High
- May 13, 2025
Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
Improper Handling of Insufficient Permissions or Privileges
May 2025: Microsoft Dataverse Remote Code Execution Vulnerability
CVE-2025-47732
8.7 - High
- May 08, 2025
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
Marshaling, Unmarshaling
Mar 2025: Microsoft Dataverse Remote Code Execution Vulnerability
CVE-2025-29807
8.7 - High
- March 21, 2025
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
Marshaling, Unmarshaling
Mar 2025: Microsoft Dataverse Elevation of Privilege Vulnerability
CVE-2025-24053
7.2 - High
- March 13, 2025
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
AuthZ
Oct 2024: Microsoft Dataverse Elevation of Privilege Vulnerability
CVE-2024-38139
8.7 - High
- October 15, 2024
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
authentification
Jun 2024: Microsoft Dataverse Remote Code Execution Vulnerability
CVE-2024-35260
8 - High
- June 27, 2024
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
Untrusted Path
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Dataverse or by Microsoft? Click the Watch button to subscribe.