A critical (CVSS 9.3) privilege escalation vulnerability in Microsoft Power Apps allows a remote, anonymous attacker to elevate their privileges. The vulnerability affects Microsoft Power Apps as of August 6, 2026, and a mitigation is available.
[WID-SEC-2026-2688] Microsoft Power Apps: Schwachstelle ermöglicht Privilegieneskalation CVSS Base Score 9.3 (kritisch) CVSS Temporal Score 8.1 (hoch) Remoteangriff ja Datum 06.08.2026 Stand 07.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Windows Produktbeschreibung Microsoft Power Apps ist eine Plattform zur Entwicklung von Low-Code-Anwendungen für Web und mobile Geräte. Produkte 06.08.2026 Microsoft Power Apps Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Microsoft Power Apps ausnutzen, um seine Privilegien zu erhöhen. CVE Informationen Versionshistorie Feedback zum Advisory geben