CyberICT

CVE-2026-20960

Microsoft · Published January 16, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

PowerApps Desktop Client Remote Code Execution Vulnerability. Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

Affected Products

  • Microsoft Power Apps Desktop Client

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C