Description
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-08-06
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network, potentially gaining full control of the application and its underlying data. The vulnerability is a classic access control weakness (CWE‑285) and can lead to unauthorized system access, data exposure, or manipulation by an attacker who originally had no privileges.

Affected Systems

Microsoft Power Apps instances are affected; no specific version information is provided, so all instances that have not applied the latest security updates may be vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve network access to the Power Apps environment, and an attacker would need to exploit the flawed authorization checks to elevate privileges. Given the high score, the risk is significant, especially in unprotected or poorly segmented environments.

Generated by OpenCVE AI on August 7, 2026 at 01:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any available Microsoft Power Apps security updates to remove the authorization flaw.
  • Restrict network access to Power Apps instances by configuring firewall rules or network segmentation to limit exposure to untrusted networks.
  • Review and enforce least privilege role assignments within Power Apps, ensuring users only have the permissions required for their job functions.

Generated by OpenCVE AI on August 7, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Power Apps Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft power-apps
Weaknesses CWE-285
CPEs cpe:2.3:a:microsoft:power-apps:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft power-apps
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Power-apps
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-07T00:56:41.996Z

Reserved: 2026-07-02T16:05:24.069Z

Link: CVE-2026-59118

cve-icon Vulnrichment

Updated: 2026-08-07T00:56:37.925Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:30:04Z

Weaknesses