Server-Side Request Forgery in Power Automate by Microsoft
CVE-2026-65818

8.5HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
3 September 2026

What is CVE-2026-65818?

A server-side request forgery vulnerability exists in Power Automate that allows an unauthorized attacker to send crafted requests to internal services. By exploiting this flaw, an attacker can potentially elevate privileges over the network, accessing restricted resources and sensitive information that should remain protected. Users are advised to apply the latest security updates to mitigate this risk.

Affected Version(s)

Microsoft Power Platform -

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.