🟠 High | Source: Microsoft Security Response Center
A vulnerability in Microsoft Power Apps allows an attacker on a network to gain elevated privileges without proper authorisation. This stems from improper authorisation controls within the platform, meaning an attacker could access resources or perform actions beyond their permitted scope. Power Apps is widely used across enterprises for business application development, making the potential blast radius significant.
Security Architect’s Take: Review access controls and audit logs for your Power Apps environments immediately, and apply any Microsoft-issued patches or mitigations without delay. Additionally, enforce least-privilege principles on Power Apps connectors and restrict network-level access to Power Apps environments where possible.
Original advisory: CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability