CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-47733

CVSS 9.1v3.1pub. 2025-05-08upd. 2025-05-21

Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network

🤖 AI Analysis
How it works

An attacker without any permissions and without user interaction can force the Microsoft Power Apps server to execute network requests on behalf of the server — a classic SSRF (CWE-918) mechanism. This enables directing queries to internal network resources that are normally not accessible from the outside. In this way, an attacker can read data from resources available on the server side, including potentially internal services, environment metadata, or other sensitive information.

Impact

An attacker can gain unauthorized access to sensitive information and compromise data integrity (High Confidentiality, High Integrity according to CVSS vector). Exploitation may lead to further reconnaissance of the organization's internal infrastructure.

Mitigation & patch

Apply patches available from the vendor in accordance with references published by Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47733

Who is affected

Microsoft Power Apps — versions indicated in the vendor's references (Microsoft Security Response Center)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Microsoft Power Apps

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SSRF
CWE
References

Related vulnerabilities

CVE-2026-59118CRITICAL9.3same product

Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-26149CRITICAL9.0PL ✓same product

Podatność spoofing w Microsoft Power Apps — improper neutralization

CVE-2026-32172HIGH8.0same product

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over ...

CVE-2026-20960HIGH8.0same product

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

CVE-2023-32052MEDIUM5.4same product

Microsoft Power Apps (online) Spoofing Vulnerability