CVE-2026-20960
Microsoft · Published January 16, 2026
8.0
CVSS v3.1
HIGHPatch availableGet patch
Description
PowerApps Desktop Client Remote Code Execution Vulnerability. Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Affected Products
- Microsoft Power Apps Desktop Client
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C