CVE-2026-32172
Microsoft · Published April 23, 2026
8.0
CVSS v3.1
HIGHPatch availableGet patch
Description
Microsoft Power Apps Remote Code Execution Vulnerability. Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.
Affected Products
- Microsoft Power Apps
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C