CVE-2026-77897
Microsoft · Published September 8, 2026
7.0
CVSS v3.1
HIGHPatch availableGet patch
Description
Microsoft Power Automate Desktop Elevation of Privilege Vulnerability. Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
Affected Products
- Power Automate for Desktop
- Power Automate agent for virtual desktops
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C