CyberICT

CVE-2026-59118

Microsoft · Published August 6, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Microsoft Power Apps Elevation of Privilege Vulnerability. Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.

Affected Products

  • Microsoft Power Apps

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C