<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>CVE-2026-47647 on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/cve-2026-47647/</link><description>Recent content in CVE-2026-47647 on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 18 Jun 2025 14:00:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/cve-2026-47647/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-47647: Dynamics 365 Privilege Escalation</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-47647-dynamics-365-elevation-of-privilege/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-47647-dynamics-365-elevation-of-privilege/</guid><description>CVE-2026-47647 is a Dynamics 365 elevation of privilege flaw allowing authenticated attackers to escalate permissions over a network. Patch now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47647">Microsoft Security Response Center</a></p>
<hr>
<p>A flaw in Microsoft Dynamics 365 allows an already-authenticated attacker to gain higher privileges than they should have, purely over the network — no physical access required. This means a low-privileged user or compromised account could be leveraged to access sensitive business data or administrative functions within Dynamics 365. Given how widely Dynamics 365 is used for CRM and ERP workflows, the potential business impact is significant.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit current Dynamics 365 role assignments and apply the least-privilege principle immediately — remove any unnecessary elevated roles whilst Microsoft&rsquo;s patch is applied. Prioritise patching for tenants where Dynamics 365 is integrated with other Azure services or holds sensitive customer and financial data.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47647">CVE-2026-47647 Dynamics 365 Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item></channel></rss>