Impact
The vulnerability is a server‑side request forgery in Power Automate that allows an attacker who already has authorized access to the service to send requests to arbitrary internal URLs. This can be used to reach protected network resources that the user normally cannot access, effectively raising their network privileges (inferred). The flaw is identified as CWE‑918 and can lead to unauthorized data exposure or lateral movement.
Affected Systems
Microsoft Power Platform, specifically Power Automate, with no version information provided in the current advisory. Users of any configuration that uses Power Automate flows within the platform are potentially affected.
Risk and Exploitability
The advisory assigns a CVSS score of 8.5, indicating a high impact. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers require existing authorized access to Power Automate and must target internal network resources via crafted outbound requests. The risk is high for environments where Power Automate has broad network reach and where internal endpoints lack stringent access controls.
OpenCVE Enrichment