Improper Authorization in Microsoft Power Apps Allows Unauthorized Privilege Escalation
CVE-2026-59118

9.3CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
6 August 2026

What is CVE-2026-59118?

The vulnerability in Microsoft Power Apps arises from improper authorization mechanisms, which can be exploited by an unauthorized attacker. If successfully triggered, this vulnerability allows the attacker to escalate privileges over the network, compromising the integrity of the application and potentially leading to unauthorized access to sensitive information. Organizations using Microsoft Power Apps should prioritize applying the latest security updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Microsoft Power Apps -

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.