Skip to content
MicrosoftCVE-2026-40375

Microsoft Dynamics Business Central: missing authorization

Medium6.5CVE-2026-40375 · Published Aug 11, 2026 · updated Aug 13, 2026

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

Microsoft advisory

Affected versions

PackageAffectedFixed in
Microsoft Dynamics 365 Business Central 2024 Release Wave 2
Product
all versionsNo fix yet
Microsoft Dynamics 365 Business Central 2026 Release Wave 1
Product
>= 28.0, < 28.0.5093828.0.50938
Microsoft Dynamics 365 Business Central Release Wave 1 2025
Product
>= 26.0, < 26.0.5078826.0.50788
Microsoft Dynamics 365 Business Central Release Wave 2 2025
Product
>= 27.0, < 27.0.5078927.0.50789
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-862

More Microsoft advisories

All Microsoft

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.