CVE-2026-88131 is a critical (CVSS 9.8) deserialization vulnerability in Microsoft Dataverse that an unauthorized attacker can use to execute code over a network.
What Is It
The NVD description is: "Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network." The weakness is classified as CWE-502 (Deserialization of Untrusted Data). Microsoft ([email protected]) is the CVE source. The record was published on 2026-10-08, and NVD lists its status as "Received," so NVD has not finished its analysis yet.
Why It Matters
Microsoft rated the flaw 9.8, which is CRITICAL, using the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That vector means:
- Attack vector: Network
- Attack complexity: Low
- Privileges required: None
- User interaction: None
- Impact: High to confidentiality, integrity, and availability
An attacker needs no credentials and no help from a user, and the attack is not complex. The exploitability subscore is 3.9 and the impact subscore is 5.9.
No CISA Known Exploited Vulnerabilities (KEV) entry was provided for this CVE. Active exploitation is not confirmed by KEV at this time.
What's Vulnerable
- Vendor: Microsoft
- Product: Microsoft Dataverse
- Versions: Listed as "-" (affected). The record does not give a specific version range.
Microsoft tagged the CVE as an exclusively-hosted-service, which means the affected product runs as a service hosted by Microsoft. The supplied NVD data does not list specific CPEs.
Patch Status
The supplied records do not describe a specific patch, fixed version, or required customer action. There is no KEV entry, so no CISA remediation deadline or required action applies. The "exclusively-hosted-service" tag means Microsoft runs the affected service. Customers should check the MSRC advisory below for Microsoft's official guidance on remediation and on whether they need to do anything.