External risk intelligence

Microsoft Power Pages Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-23652

Microsoft Power Pages is a platform specifically designed to build and host public-facing websites and web applications. By design, these services are intended to be accessible from the internet to support external users, making the attack surface public-facing in normal deployments.

Command Injection

Microsoft Power Pages

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Microsoft Power Pages that could allow an attacker to run unauthorized code remotely. The issue stems from how the system handles special commands, potentially enabling malicious code execution without any required user interaction or prior access.

  • Unauthorized remote code execution is possible.
  • This affects public-facing web applications.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted commands over a network to a vulnerable instance of Microsoft Power Pages. This could allow them to execute arbitrary code on the underlying system, potentially leading to a complete compromise of the affected environment.

  • Network access to a vulnerable instance.
  • Sending malicious commands to the application.
  • Unauthorized remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthorized attacker to execute arbitrary code over a network, potentially impacting the confidentiality, integrity, and availability of the affected system when accessed by external users.

  • System data and service behavior.
  • Network-based code execution.
  • Unauthorized code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Microsoft Power Pages, being a platform for public-facing websites, likely involves collaboration between application owners responsible for the content and functionality, and infrastructure or platform teams managing the underlying environment. Initial actions should focus on identifying all Power Pages instances, assessing their network exposure and business criticality, and pinpointing the accountable owner for each instance to plan remediation.

  • Application and platform teams should own.
  • Verify network exposure and business criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Microsoft Power Pages?

Microsoft Power Pages is a low-code software platform used to create, host, and manage professional-grade business websites. It is widely used by organizations to build external-facing portals that allow customers or partners to interact with business data and services directly over the web.

What does command injection mean in CVE-2026-23652?

This vulnerability is classified as CWE-77, which occurs when a system fails to properly filter special characters in user input. An attacker can use these characters to "inject" their own malicious commands, tricking the software into executing unauthorized instructions on the underlying server instead of just processing the intended data.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by sending specially crafted network packets containing malicious commands to a target Power Pages instance. The vulnerability does not rely on local access or specific user actions; it is triggered remotely. Simply accessing the site legitimately as a standard user does not initiate the flaw; the malicious payload must be explicitly included in the communication.

Is my Power Pages instance at risk?

Because Microsoft Power Pages is explicitly designed to host public-facing websites, Halo Surface Signal identifies these instances as inherently internet-accessible. If you are using this platform to host a site, your environment is likely exposed to network-based threats by design, making this vulnerability highly relevant to your public-facing infrastructure.

What should I do first to address this CVE?

Your priority is to identify every Power Pages instance currently in use across your organization. Once you have a complete inventory, verify the business criticality of each site and coordinate with the respective application owners to confirm their status and prepare for the necessary security updates or configuration changes provided by the vendor.

References