CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-26149

CVSS 9.0v3.1pub. 2026-04-14upd. 2026-05-07

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.

🤖 AI Analysis
How it works

The vulnerability results from insufficient processing (sanitization) of special sequences — escape, meta, or control characters — in Microsoft Power Apps. An authenticated attacker can deliver crafted input data containing such sequences that are not properly neutralized by the application. This requires interaction from the victim side (UI:R), indicating that an attacker can, for example, trick a user into opening malicious content. This makes it possible to conduct a spoofing attack in a network context with an impact on confidentiality, integrity, and availability that exceeds the component boundary (Scope:Changed).

Impact

An attacker can conduct an effective spoofing attack over the network, potentially forging identity or content presented to users, which may lead to violations of confidentiality, integrity, and availability of data processed by Microsoft Power Apps.

Mitigation & patch

Patches available from the vendor should be applied according to references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26149

Who is affected

Microsoft Power Apps — versions indicated in the vendor's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Microsoft Power Apps

    APP
    Microsoft
    < 3.26032.10.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-59118CRITICAL9.3same product

Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-47733CRITICAL9.1PL ✓same product

SSRF w Microsoft Power Apps umożliwia nieautoryzowane ujawnienie informacji

CVE-2026-32172HIGH8.0same product

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over ...

CVE-2026-20960HIGH8.0same product

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

CVE-2023-32052MEDIUM5.4same product

Microsoft Power Apps (online) Spoofing Vulnerability