Security Feature Bypass in Microsoft Power Apps
CVE-2026-26149
9CRITICAL
What is CVE-2026-26149?
Improper handling of escape, meta, or control sequences in Microsoft Power Apps enables an authorized attacker to circumvent a critical security feature, potentially exposing sensitive data over a network. This vulnerability highlights the importance of robust input validation and security protocols within enterprise applications.
Affected Version(s)
Microsoft Power Apps 1710 (9.2.23071.136) < 3.26032.10.0