Improper Authorization in Microsoft Power Apps Allows Unauthorized Privilege Escalation
CVE-2026-59118
9.3CRITICAL
What is CVE-2026-59118?
The vulnerability in Microsoft Power Apps arises from improper authorization mechanisms, which can be exploited by an unauthorized attacker. If successfully triggered, this vulnerability allows the attacker to escalate privileges over the network, compromising the integrity of the application and potentially leading to unauthorized access to sensitive information. Organizations using Microsoft Power Apps should prioritize applying the latest security updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Microsoft Power Apps -