Sceawere

Vulnerability Detail

CVE-2026-66301UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Dynamics 365 Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft Dynamics 365 (on-premises) version 9.1
Attack Type
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-11T17:19:01.277Z",
  "pubdate": "2026-08-11T17:19:01.277Z",
  "executiveSummary": "An information disclosure vulnerability exists in Microsoft Dynamics 365 (on-premises) that allows an unauthorized actor to access sensitive information over a network. The vulnerability involves the exposure of confidential data due to improper access controls within the affected software. The primary impact of this security flaw is unauthorized information disclosure, potentially leading to the leakage of internal system data or operational details. The affected product is Microsoft Dynamics 365 (on-premises). The risk implications include the potential compromise of data confidentiality, which could be leveraged by malicious actors for reconnaissance or subsequent attacks. To exploit this vulnerability, an attacker must possess authenticated access to the network, allowing them to interact with vulnerable endpoints and extract sensitive data that should otherwise be restricted. No complex exploitation requirements are specified beyond the need for network connectivity and appropriate authorization levels as defined by the attack vector.",
  "technicalDetails": "The vulnerability stems from improper handling of sensitive data exposure within Microsoft Dynamics 365 (on-premises), allowing authorized entities to access information outside their intended privilege boundaries. The root cause is centered around inadequate authorization checks or flawed data filtering mechanisms within the application logic, which fails to properly restrict access to sensitive resources over the network. The vulnerable component involves network-accessible endpoints or services within the Microsoft Dynamics 365 (on-premises) architecture that process and return sensitive data payloads to clients. Exploitation occurs when an attacker with network access leverages valid credentials or sessions to interact with these vulnerable endpoints. The attack flow begins with the attacker establishing network connectivity to the target Microsoft Dynamics 365 (on-premises) deployment. Subsequently, the attacker sends specially crafted requests or queries to the vulnerable application components that handle sensitive data processing. Because the underlying access control enforcement or data sanitization is insufficient, the server processes the request and improperly returns the confidential information within the response payload. The authentication requirements stipulate that the attacker must be an authorized actor, indicating that some level of valid credentials or session context is necessary to reach the vulnerable functionality. The privilege requirements are aligned with the perspective of an authenticated user, but the flaw enables the retrieval of data exceeding the user's intended authorization scope. The network exposure is characterized by the ability to exploit the vulnerability remotely over a network connection targeting the on-premises deployment. Post-exploitation impact is strictly limited to information disclosure, where the acquired sensitive data can be analyzed by the attacker to map internal system configurations, user data, or business logic, thereby facilitating further targeting or reconnaissance phases."
}
CVE-2026-66301: Microsoft Dynamics 365 Information Disclosure (MEDIUM Severity, CVSS: 6.5) - Sceawere