CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-32210

CVSS 9.3v3.1pub. 2026-04-23upd. 2026-05-05

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

🤖 AI Analysis
How it works

An attacker, without possessing any privileges, can induce the Microsoft Dynamics 365 server to send crafted network requests on behalf of the server (SSRF). This mechanism allows traffic to be redirected through the application server to internal or external network resources, resulting in the possibility of server identity spoofing. The vulnerability requires user interaction (e.g., opening a malicious link), indicating a possible attack vector through phishing or crafted content.

Impact

An attacker can conduct network spoofing, potentially gaining access to sensitive data (high confidentiality) or modifying data (high integrity) by forcing the server to execute requests to internal or external resources.

Mitigation & patch

Security patches available from the vendor should be applied in accordance with references published in the Microsoft Security Response Center (MSRC): https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32210

Who is affected

Microsoft Dynamics 365 (Online) — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Microsoft Dynamics 365

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SSRF
CWE
References

Related vulnerabilities

CVE-2026-47647CRITICAL9.9PL ✓same product

Privilege escalation w Microsoft Dynamics 365 przez niewłaściwą kontrolę dostępu

CVE-2026-42833CRITICAL9.1PL ✓same product

Code injection w Microsoft Dynamics 365 On-Premises — zdalne wykonanie kodu

CVE-2026-42898CRITICAL9.9PL ✓same product

Code injection w Microsoft Dynamics 365 (on-premises) umożliwiający RCE

CVE-2024-38182CRITICAL9.0PL ✓same product

Słabe uwierzytelnianie w Microsoft Dynamics 365 umożliwia privilege escalation

CVE-2026-65815HIGH8.8same product

Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to exe...