VYPR
advisoryPublished Sep 14, 2026· 1 source

Microsoft Launches Bug Bounty for AI Flaws in Dynamics 365 and Power Platform

Microsoft is offering up to $30,000 for critical AI vulnerabilities in Dynamics 365 and Power Platform, focusing on inference manipulation and information disclosure.

Microsoft has announced a new bug bounty program specifically targeting critical artificial intelligence vulnerabilities within its Dynamics 365 and Power Platform ecosystems. Security researchers can earn up to $30,000 for discovering and reporting flaws that could lead to AI inference manipulation or inferential information disclosure. This initiative underscores Microsoft's commitment to securing its rapidly expanding AI-driven business solutions.

The bounty program covers a wide array of potential vulnerabilities, including those residing in Microsoft-hosted services as well as third-party or open-source components embedded within them. To qualify for a payout, researchers must demonstrate a tangible security impact on an in-scope service. The tiered payout structure rewards high-quality reports documenting critical impacts, with the maximum $30,000 reserved for "Inference Manipulation" or "Inferential Information Disclosure" findings submitted with high-quality documentation. Medium and low-quality reports for critical impacts, as well as important-severity findings, will receive lesser amounts, while moderate and low-severity AI submissions are not eligible for payment under this specific bounty category.

The scope of the program is extensive, reflecting the critical nature of the Dynamics 365 and Power Platform services, which handle sensitive business data and automate complex workflows. Eligible targets include a broad range of Dynamics 365 applications such as Sales, Customer Service, Finance, Commerce, Human Resources, Business Central, Contact Center, Customer Insights, and Supply Chain Management. On-premises Dynamics products are also included. Furthermore, the bounty extends to core Power Platform services like Power Apps, Power Automate, Copilot Studio, Power Pages, Power Admin, AI Builder, and Dataverse.

Beyond the specialized AI vulnerability payouts, Microsoft's broader bug bounty program continues to offer significant rewards for other critical security flaws. Up to $20,000 is available for critical remote code execution (RCE) vulnerabilities affecting in-scope cloud and service components. High-impact cross-tenant information disclosure scenarios can also yield up to $20,000. Additionally, critical elevation of privilege or information disclosure flaws are eligible for up to $12,000, while critical spoofing or tampering reports can earn up to $8,000. Unique high-impact vectors, such as Dataverse privilege escalation and Plugin Sandbox "guest-to-host" escapes, may even receive a 20% multiplier on their award.

Microsoft has outlined specific requirements for AI vulnerability submissions, mandating that findings meet its Critical or Important severity definitions and be reproducible on the latest, fully patched versions of eligible products. Researchers are required to submit their findings through the Microsoft Security Response Center (MSRC) Researcher Portal. Crucial details such as the Power Platform or Dynamics environment ID, the username used during testing, and confirmation of whether the bug aligns with a high-impact scenario are necessary for submission. Comprehensive reproduction steps, proof-of-concept materials, affected versions, and a clear explanation of the potential attacker impact are vital for accelerating validation and potentially securing a higher award.

It is important to note that the program explicitly distinguishes between exploitable AI security failures and less critical issues. Excluded from bounty consideration are prompt injections that only affect the attacker, hallucinated code execution, attempts to reveal system prompts or meta-prompts, and content-safety issues. Common vulnerabilities like publicly known bugs, denial-of-service attacks, blind cross-site scripting, dependency confusion, and configuration-dependent weaknesses are also generally out of scope. Microsoft emphasizes responsible testing practices, requiring researchers to operate only within authorized accounts and tenants, cease testing immediately upon discovering unauthorized data, and avoid disruptive activities such as post-exploitation, lateral movement, or excessive traffic generation.

Microsoft strongly advises researchers to mark their testing tenants with "MSOBB" where feasible and to adhere strictly to coordinated vulnerability disclosure principles. This ensures that findings are communicated to Microsoft engineers without exposing customers or production services to undue risk. The company's proactive approach through bug bounties aims to identify and remediate potential threats before they can be exploited, thereby enhancing the security posture of its widely adopted business applications and AI integrations.

Synthesized by Vypr AI