CyberICT

CVE-2026-32172

Microsoft · Published April 23, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Microsoft Power Apps Remote Code Execution Vulnerability. Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

Affected Products

  • Microsoft Power Apps

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C