Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.
The vulnerability results from insufficient processing (sanitization) of special sequences — escape, meta, or control characters — in Microsoft Power Apps. An authenticated attacker can deliver crafted input data containing such sequences that are not properly neutralized by the application. This requires interaction from the victim side (UI:R), indicating that an attacker can, for example, trick a user into opening malicious content. This makes it possible to conduct a spoofing attack in a network context with an impact on confidentiality, integrity, and availability that exceeds the component boundary (Scope:Changed).
An attacker can conduct an effective spoofing attack over the network, potentially forging identity or content presented to users, which may lead to violations of confidentiality, integrity, and availability of data processed by Microsoft Power Apps.
Patches available from the vendor should be applied according to references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26149
Microsoft Power Apps — versions indicated in the vendor's references
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HMicrosoft Power Apps
APPMicrosoft< 3.26032.10.0
Related vulnerabilities
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
SSRF w Microsoft Power Apps umożliwia nieautoryzowane ujawnienie informacji
Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over ...
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Microsoft Power Apps (online) Spoofing Vulnerability