CVE-2026-40375: Microsoft Dynamics Business Central Information Disclosure Vulnerability

Overview

Severity
Medium (CVSS 6.5)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Aug
Released
2026-08-11

Description

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

FAQ

What type of information could be disclosed by this vulnerability? Exploiting this vulnerability could allow the disclosure of credentials. What action should customers using Microsoft Dynamics 365 Business Central 2024 Release Wave 2 (version 25.x) take? Version 25.x has reached the end of support and will not receive a security update for this vulnerability. Customers should upgrade to version 26.14 or later; see the Dynamics 365 Business Central on-premises lifecycle policy and KB 5100263 for more information.

Affected Products (4)

Microsoft Dynamics

  • Microsoft Dynamics 365 Business Central 2024 Release Wave 2
  • Microsoft Dynamics 365 Business Central Release Wave 1 2025
  • Microsoft Dynamics 365 Business Central 2026 Release Wave 1
  • Microsoft Dynamics 365 Business Central Release Wave 2 2025

Security Updates (3)

Acknowledgments

<a href="https://www.linkedin.com/in/nhienit/">nhienit</a> with <a href="https://galaxy.one/">Galaxy One</a>

Revision History

  • 2026-08-11: Information published.