critical · CVSS v3 9
CVE-2026-77903
CVE-2026-77903 is a critical authentication bypass in Microsoft Dataverse that lets an attacker spoof credentials and gain elevated privileg
Overview
CVE-2026-77903 is a critical authentication bypass in Microsoft Dataverse that lets an attacker spoof credentials and gain elevated privileges over a network. The flaw can be exploited without valid credentials, enabling unauthorized access to sensitive data and administrative functions. It affects all organizations that host or consume Dataverse services.
Description
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
Impact
The vulnerability compromises confidentiality and integrity by allowing attackers to impersonate users and elevate privileges. It can lead to unauthorized data access, modification, or deletion within Dataverse environments. Administrators and end‑users are at risk, as attackers can bypass authentication controls and potentially affect downstream applications that rely on Dataverse data.
Remediation
1. Apply the latest Microsoft patch or update for Dataverse and related Power Platform components. 2. Enforce multi‑factor authentication (MFA) for all Dataverse users and administrators. 3. Review and tighten role‑based access controls, ensuring least‑privilege principles. 4. Enable network segmentation and firewall rules to restrict inbound traffic to Dataverse endpoints. 5. Monitor authentication logs for suspicious spoofing patterns and set up alerts for repeated failed or unusual login attempts.
Risk context
With a CVSS v3 score of 9.0 and classified as critical, this flaw demands immediate attention. Although EPSS data is not available, the high severity indicates a significant threat to organizations using Microsoft Dataverse.
Affected products
- Microsoft Dataverse
- Power Platform
- Dynamics 365
- Power Apps
- Power Automate
- Power BI (Dataverse connector)
- Azure AD (Dataverse integration)
- Microsoft Cloud App Security (Dataverse monitoring)
Scores
- Severity
- critical
- CVSS v2
- 7.6
- CVSS v3
- 9
- CVSS v4
- —
- EPSS
- —