Security Feature Bypass in Microsoft Power Apps
CVE-2026-26149
9CRITICAL
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-26149?
Improper handling of escape, meta, or control sequences in Microsoft Power Apps enables an authorized attacker to circumvent a critical security feature, potentially exposing sensitive data over a network. This vulnerability highlights the importance of robust input validation and security protocols within enterprise applications.
Affected Version(s)
Microsoft Power Apps Desktop Client 1.0.0 < 3.26032.10.0