Impact
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network, potentially gaining full control of the application and its underlying data. The vulnerability is a classic access control weakness (CWE‑285) and can lead to unauthorized system access, data exposure, or manipulation by an attacker who originally had no privileges.
Affected Systems
Microsoft Power Apps instances are affected; no specific version information is provided, so all instances that have not applied the latest security updates may be vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve network access to the Power Apps environment, and an attacker would need to exploit the flawed authorization checks to elevate privileges. Given the high score, the risk is significant, especially in unprotected or poorly segmented environments.
OpenCVE Enrichment