CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-42898

CVSS 9.9v3.1pub. 2026-05-12upd. 2026-05-14

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

🤖 AI Analysis
How it works

The vulnerability is caused by improper control of code generation (CWE-94 — Improper Control of Generation of Code). An attacker with an account in the system can submit specially crafted data over the network, which is then interpreted and executed as code by the application. The network attack vector with low complexity and no required user interaction significantly lowers the threshold for exploiting the vulnerability. The attack scope extends beyond the vulnerable component, meaning the ability to impact resources outside the direct Dynamics 365 environment.

Impact

An attacker can gain full control of the system through remote code execution, leading to violation of confidentiality, integrity, and availability of data and infrastructure.

Mitigation & patch

Apply patches available from the vendor according to references published in Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42898

Who is affected

Microsoft Dynamics 365 (on-premises) — specific versions indicated in vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42898)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Microsoft Dynamics 365

    APP
    Microsoft
    9.1.1.914 – 9.1.45.11 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-47647CRITICAL9.9PL ✓same product

Privilege escalation w Microsoft Dynamics 365 przez niewłaściwą kontrolę dostępu

CVE-2026-42833CRITICAL9.1PL ✓same product

Code injection w Microsoft Dynamics 365 On-Premises — zdalne wykonanie kodu

CVE-2026-32210CRITICAL9.3PL ✓same product

SSRF w Microsoft Dynamics 365 umożliwia spoofing sieciowy

CVE-2024-38182CRITICAL9.0PL ✓same product

Słabe uwierzytelnianie w Microsoft Dynamics 365 umożliwia privilege escalation

CVE-2026-65815HIGH8.8same product

Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to exe...