CVE-2026-26149
Microsoft · Published April 14, 2026
9.0
CVSS v3.1
CRITICALPatch availableGet patch
Description
Microsoft Power Apps Desktop Client Spoofing Vulnerability. Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.
Affected Products
- Microsoft Power Apps Desktop Client
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H/E:U/RL:T/RC:C