External risk intelligence

Microsoft Power Apps Privilege Escalation Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-59118

Microsoft Power Apps is a cloud-based service platform commonly deployed as a public-facing web and API environment. As a SaaS application, it is designed to be accessible over the network to authorized users and integrated services, making it a common target for internet-reachable interaction.

Microsoft Power Apps

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in Microsoft Power Apps, allowing unauthorized network access to elevate privileges. This flaw could enable attackers to gain higher levels of control over the system. The primary concern at this time is to confirm if our organization utilizes the affected technology and assess the potential exposure.

  • Unauthorized privilege elevation via network access.
  • Critical vulnerability in Microsoft Power Apps.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could gain unauthorized privileges by exploiting an improper authorization flaw in Microsoft Power Apps. This vulnerability may be reachable over a network, potentially allowing an attacker to elevate their access after a user interacts with a malicious element.

  • Requires network access.
  • Triggered by user interaction.
  • Risk of privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

Microsoft Power Apps, when used in supported configurations, could allow an unauthorized attacker to elevate their privileges over a network. This could potentially affect system data and user data, depending on the specific application and its configurations.

  • System and user data.
  • Unauthorized network access.
  • Privilege escalation.

Operational Fix

Recommended remediation, mitigation, and detection steps

System owners and application teams are likely responsible for addressing improper authorization in Microsoft Power Apps. The first step is to identify all instances of Power Apps within the environment, assess their reachability and business criticality, and confirm the accountable owner for each instance to prioritize remediation efforts.

  • Application owners should assume responsibility.
  • Verify network reachability and business impact.
  • Plan coordinated remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Microsoft Power Apps?

Microsoft Power Apps is a low-code cloud-based service platform that enables organizations to build and run custom business applications. It provides a structured environment where teams can connect to various data sources and create automated workflows. Because it is a SaaS platform, it is commonly used to host web-based tools and APIs that facilitate internal processes or customer-facing operations, serving as a critical bridge between data and user interaction.

What does improper authorization mean for CVE-2026-59118?

This vulnerability is classified as CWE-285, which refers to improper authorization. In simple terms, the system fails to correctly verify or enforce the specific permissions a user should have. For this CVE, that weakness allows an unauthorized person to bypass security checks and gain higher levels of privilege—essentially acting as a more powerful user or administrator than they are supposed to be.

How is CVE-2026-59118 triggered?

An attacker needs network access to reach the service to initiate this vulnerability. Importantly, the exploit does not trigger automatically; it requires a user to perform an action, such as interacting with a malicious element within the platform. If no user interacts with the crafted content, the specific conditions for this privilege escalation are not met.

Is my organization at risk for CVE-2026-59118?

Halo Surface Signal notes that Microsoft Power Apps is frequently deployed as a public-facing web and API environment. Because it is designed to be accessible over the network for integration and user access, instances that are internet-facing have a higher potential for reachability. You should focus on identifying any Power Apps configurations that are exposed to external network traffic, as these are the primary targets.

What should I do first to address this vulnerability?

Start by auditing your environment to create an inventory of all active Microsoft Power Apps instances. Once identified, categorize these apps based on their business criticality and network reachability to determine which might be exposed to external actors. Finally, engage the application owners responsible for each instance to coordinate the necessary security updates or configuration changes.

References