You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
erp privilege escalation
About this tag
The erp privilege escalation tag covers a confirmed elevation-of-privilege vulnerability in Microsoft Dynamics 365 Business Central, tracked as CVE-2026-40417. This issue allows an authorized local attacker to gain SYSTEM privileges through weak authentication. The vulnerability is rated Important severity, and the CVSS temporal metric indicates it is no longer hypothetical. For organizations using Business Central, the focus is on hardening ERP identity boundaries to prevent privilege escalation. The tag content discusses the technical details of the vulnerability, its impact on enterprise systems, and the importance of applying the patch to secure ERP environments against local privilege escalation attacks.
Microsoft published CVE-2026-40417 on May 12, 2026, describing an Important-severity elevation-of-privilege vulnerability in Microsoft Dynamics 365 Business Central that can let an authorized local attacker gain SYSTEM privileges through weak authentication. The most important word in...