Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-77903 2026-09-17

CVE-2026-77903: Critical Authentication Bypass in Microsoft Dataverse

"Microsoft disclosed a critical (CVSS 9.0) authentication bypass by spoofing in Microsoft Dataverse that lets an unauthenticated attacker elevate privileges over a network."

Microsoft disclosed a critical (CVSS 9.0) authentication bypass by spoofing in Microsoft Dataverse that lets an unauthenticated attacker elevate privileges over a network.

What Is It

CVE-2026-77903 is an authentication bypass by spoofing vulnerability in Microsoft Dataverse, tracked as CWE-290. Per Microsoft's description, the flaw "allows an unauthorized attacker to elevate privileges over a network."

The CVSS 3.1 vector is AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H, for a base score of 9.0 (CRITICAL). The attack is reachable over the network, requires no privileges and no user interaction, and the scope is Changed; meaning successful exploitation affects resources beyond the vulnerable component. Confidentiality, integrity, and availability impacts are all rated High. Attack complexity is High, which is the only meaningful brake on the score; the exploitability subscore is 2.2 against an impact subscore of 6.0.

Why It Matters

No privileges and no user interaction, combined with a changed scope and full CIA impact, is close to the worst-case shape for a cloud service vulnerability. An attacker who can spoof authentication against Dataverse is positioned to act as a privileged identity and reach data and resources outside the initially compromised boundary.

The source data for this brief contains no exploitation reporting for CVE-2026-77903. Defenders tracking exploitation status or any applicable federal remediation deadline should consult CISA's Known Exploited Vulnerabilities catalog directly rather than relying on this brief.

What's Vulnerable

Microsoft tagged the CVE exclusively-hosted-service. That tag means the affected code runs only in Microsoft's hosted environment, which is consistent with the absence of any affected CPE entries or discrete version ranges in the NVD record. There is no customer-installed build to inventory.

Patch Status

The NVD record was published 2026-09-17 with a vulnerability status of Received, meaning NVD analysis was not yet complete. No patch, build number, workaround, or mitigation guidance is present in the supplied data.

Because this is an exclusively hosted service, remediation is expected to be applied by Microsoft on the service side rather than by customers. The MSRC update guide entry below is the authoritative source for current status and any required customer action.

Sources