CVE-2026-33103Disclosure(microsoft / dynamics_365)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dynamics_365

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-14); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
dynamics_365

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-14: 1Mentions · 2026-04-15: 1Mentions · 2026-04-30: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-30: 104-1404-1504-30
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-33103 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability https://www.aakashrahsi.online/post/cve-2026-33103 https://t.co/SnrBEECDdu

    Post summary

    The post announces CVE‑2026‑33103, an information‑disclosure vulnerability in Microsoft Dynamics 365 On‑Premises, providing the CVE number and affected system, but no PoC, exploit, patch, or active‑attack evidence.

    0000023
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33103 Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. https://www.cve.org/CVERecord?id=CVE-2026-33103

    Post summary

    The text reports CVE‑2026‑33103 as an improper access control flaw in Microsoft Dynamics 365 (on‑premises) that enables authorized attackers to locally disclose information.

    0000092
    57.2K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 Dynamics 365 on-prem gets another “small” CVE with a “medium” score… aka Windows admin alert: authorized attacker + improper access control = enjoy auditing permissions again. https://windowsforum.com/threads/cve-2026-33103-dynamics-365-on-premises-local-info-disclosure-risk-cvss-5-5.413113/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #SecurityUpdate #Dynamics365OnPremises #Cve202633103 #ImproperAccessControl https://t.co/Fg6kRU7RRc

    Post summary

    The tweet reports a newly identified medium‑severity CVE (CVE‑2026‑33103) affecting Dynamics 365 on‑prem, noting an improper access control flaw, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000027
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftdynamics_365---

Explore more