CyberICT

CVE-2026-26149

Microsoft · Published April 14, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Microsoft Power Apps Desktop Client Spoofing Vulnerability. Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.

Affected Products

  • Microsoft Power Apps Desktop Client

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H/E:U/RL:T/RC:C