External risk intelligence

Power Automate SSRF Vulnerability Allows Privilege Escalation

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-65818

Power Automate is a widely deployed cloud-based automation and integration service that functions as an internet-facing API and web-accessible platform. Server-side request forgery in such a service typically involves interaction with external network resources or internal service endpoints, making it a commonly reachable service in many enterprise environments.

Server-Side Request Forgery

Microsoft Power Platform

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Microsoft Power Automate allows an authenticated user to potentially elevate their privileges across the network through a server-side request forgery flaw. This means an attacker with some access could trick the system into making requests on their behalf, potentially leading to unauthorized actions. The main concern is confirming the relevance and exposure of this issue within our environment.

  • Attackers can misuse automation features.
  • Limits access, enabling broader system compromise.
  • Confirm if our automation services are exposed.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to Power Automate, leveraging their existing authorized access. This would cause Power Automate to make a request to an unintended location, potentially allowing the attacker to gain elevated privileges within the system or access sensitive information.

  • Requires authorized access.
  • Triggered by a crafted network request.
  • Risk of privilege escalation and data access.

Live Threat

Current exploitation, exposure, and threat context

A server-side request forgery vulnerability in Power Automate could allow an authenticated attacker to elevate privileges over a network, potentially impacting the confidentiality, integrity, and availability of connected services and data. This could occur when the Power Automate service makes requests to unauthorized network resources on behalf of the attacker.

  • Connected services and data.
  • Forged network requests by an attacker.
  • Privilege escalation and unauthorized access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Server-side request forgery in Power Automate requires immediate attention from teams managing cloud applications and their underlying infrastructure. The first step is to locate all instances of Power Automate within your environment, assess their exposure and criticality, and identify the accountable system owners to prioritize remediation efforts.

  • Application and platform teams own the issue.
  • Verify Power Automate instance exposure and criticality.
  • Coordinate risk-based remediation planning.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Microsoft Power Platform?

Microsoft Power Platform is a suite of low-code tools designed to build custom applications, automate business workflows, and analyze data. Power Automate, a component of this platform, acts as a cloud-based service that connects various apps and services to execute automated tasks. It essentially functions as a middleman that can be instructed to perform actions across different systems, making it a central hub for organizational process automation.

What does CWE-918 mean for CVE-2026-65818?

CWE-918 refers to Server-Side Request Forgery, or SSRF. In the context of this vulnerability, it means the Power Automate service can be manipulated into sending network requests to locations it was not intended to reach. Because the server itself makes these requests, it may bypass standard security controls, allowing an attacker to interact with internal or external resources that would otherwise be off-limits.

How is this SSRF vulnerability triggered?

An attacker triggers this flaw by sending a specifically crafted request to the Power Automate service. Because this requires pre-existing authorized access, simply interacting with the service as a standard user is not enough to trigger the bug. It does not occur through normal, legitimate automation workflows; the request must be intentionally designed to deceive the server into communicating with an unauthorized target.

Why should I care about CVE-2026-65818?

Halo Surface Signal notes that Power Automate is a widely deployed, internet-facing service, which increases the likelihood of this issue being reachable. If your organization relies on Power Automate to integrate cloud and internal services, an attacker could potentially abuse this trust to escalate privileges. Because the service is web-accessible, any misconfiguration or vulnerability here can have broader impacts on your connected data and system availability.

Do I need to fix my Power Automate instances?

Yes. Your first step is to catalog all Power Automate instances within your organization to understand where this technology is active. Once identified, work with the specific application owners to determine the criticality of those instances. Prioritize this by assessing which services are connected to your Power Automate environment, as those are the areas most at risk if the service is coerced into making unauthorized network requests.

References