CVE-2026-88131

Microsoft Dataverse

Published 8 Oct 2026 · updated 9 Oct 2026 · Awaiting Analysis

9.8 Critical · CVSS 3.1, microsoft.com

Description

Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.

References