Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network
An attacker without any permissions and without user interaction can force the Microsoft Power Apps server to execute network requests on behalf of the server — a classic SSRF (CWE-918) mechanism. This enables directing queries to internal network resources that are normally not accessible from the outside. In this way, an attacker can read data from resources available on the server side, including potentially internal services, environment metadata, or other sensitive information.
An attacker can gain unauthorized access to sensitive information and compromise data integrity (High Confidentiality, High Integrity according to CVSS vector). Exploitation may lead to further reconnaissance of the organization's internal infrastructure.
Apply patches available from the vendor in accordance with references published by Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47733
Microsoft Power Apps — versions indicated in the vendor's references (Microsoft Security Response Center)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMicrosoft Power Apps
APPMicrosoftall versions
Related vulnerabilities
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
Podatność spoofing w Microsoft Power Apps — improper neutralization
Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over ...
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Microsoft Power Apps (online) Spoofing Vulnerability