CVE-2026-42898

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:dynamics_365:*:*:*:*:on-premises:*:*:*

History

No history.

Information

Published : 2026-05-12 18:17

Updated : 2026-06-17 10:48


NVD link : CVE-2026-42898

Mitre link : CVE-2026-42898

CVE.ORG link : CVE-2026-42898


JSON object : View

Products Affected

microsoft

  • dynamics_365
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')