Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
The flaw consists of improper control of code generation (CWE-250 — execution with excessive privileges) in the Microsoft Dynamics 365 component in the on-premises version. An attacker with privileges in the system can supply specially crafted input data that is interpreted and executed as code on the server side. The attack vector is network-based, requires no user interaction, and the scope of attack extends beyond the component itself (Scope: Changed), indicating the possibility of impact on other system resources.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the server, leading to complete compromise of confidentiality, integrity, and availability of the system, and potentially to takeover of control over other related infrastructure resources.
Patches available from the vendor should be applied in accordance with references published at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42833
Microsoft Dynamics 365 in on-premises version — specific versions indicated in vendor references (MSRC)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HMicrosoft Dynamics 365
APPMicrosoft9.1 – 9.1.45.11 (excl.)
Related vulnerabilities
Privilege escalation w Microsoft Dynamics 365 przez niewłaściwą kontrolę dostępu
Code injection w Microsoft Dynamics 365 (on-premises) umożliwiający RCE
SSRF w Microsoft Dynamics 365 umożliwia spoofing sieciowy
Słabe uwierzytelnianie w Microsoft Dynamics 365 umożliwia privilege escalation
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to exe...