May 2026: Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2026-40417 Published on May 12, 2026
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
Weakness Type
CWE-1390
Products Associated with CVE-2026-40417
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Dynamics 365 Business Central 2024 Release Wave 2:- Version 25.0 and below 25.2.48119 is affected.
- Version 28.0 and below 28.0.49873 is affected.
- Version 26.0 and below 26.0.48120 is affected.
- Version 27.0 and below 27.0.48102 is affected.
Exploit Probability
EPSS
0.27%
Percentile
19.40%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.