CVE-2026-40375

Summary

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft Dynamics 365 Business Central 2024 Release Wave 2-affected
MicrosoftMicrosoft Dynamics 365 Business Central 2026 Release Wave 128.0 < 28.0.50938affected
MicrosoftMicrosoft Dynamics 365 Business Central Release Wave 1 202526.0 < 26.0.50788affected
MicrosoftMicrosoft Dynamics 365 Business Central Release Wave 2 202527.0 < 27.0.50789affected

Weaknesses

  • CWE-862: CWE-862: Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References