CVE-2025-29826: Microsoft Dataverse Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.3)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Unlikely
- Patch Tuesday
- 2025-May
- Released
- 2025-05-13
- EPSS Score
- 0.61% (percentile: 69.9%)
Description
Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
FAQ
What actions do I need to take to be protected from this vulnerability
Customers who do not wish to wait for the PDU can update Dataverse by doing the following:
Open Resource Scheduling Optimization and select Upgrade to new version.
Select version 1406 from the Select target version list.
Affected Products (1)
Microsoft Dynamics
Security Updates (1)
Acknowledgments
Prasanna Kudli
Revision History
- 2025-05-13: Information published.