Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.
An attacker, without possessing any privileges, can induce the Microsoft Dynamics 365 server to send crafted network requests on behalf of the server (SSRF). This mechanism allows traffic to be redirected through the application server to internal or external network resources, resulting in the possibility of server identity spoofing. The vulnerability requires user interaction (e.g., opening a malicious link), indicating a possible attack vector through phishing or crafted content.
An attacker can conduct network spoofing, potentially gaining access to sensitive data (high confidentiality) or modifying data (high integrity) by forcing the server to execute requests to internal or external resources.
Security patches available from the vendor should be applied in accordance with references published in the Microsoft Security Response Center (MSRC): https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32210
Microsoft Dynamics 365 (Online) — versions indicated in vendor references
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NMicrosoft Dynamics 365
APPMicrosoftall versions
Related vulnerabilities
Privilege escalation w Microsoft Dynamics 365 przez niewłaściwą kontrolę dostępu
Code injection w Microsoft Dynamics 365 On-Premises — zdalne wykonanie kodu
Code injection w Microsoft Dynamics 365 (on-premises) umożliwiający RCE
Słabe uwierzytelnianie w Microsoft Dynamics 365 umożliwia privilege escalation
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to exe...