CVE-2026-40375HighCVSS 6.5
Microsoft Dynamics Business Central Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
🎯 Affected products4
- Microsoft Dynamics 365 Business Central 2024 Release Wave 2
- Microsoft Dynamics 365 Business Central 2026 Release Wave 1
- Microsoft Dynamics 365 Business Central Release Wave 1 2025
- Microsoft Dynamics 365 Business Central Release Wave 2 2025
✅ Remediation
KB5100263 (Security Update) — fixed build 26.0.50788 KB5100266 (Security Update) — fixed build 28.0.50938 KB5100265 (Security Update) — fixed build 27.0.50789