CVE-2026-26149 PUBLISHED

Microsoft Power Apps Security Feature Bypass

Assigner: microsoft
Reserved: 11.02.2026 Published: 14.04.2026 Updated: 15.04.2026

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to bypass a security feature over a network.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H/E:U/RL:T/RC:C
CVSS Score: 9

Product Status

Vendor Microsoft
Product Microsoft Power Apps
Versions
  • affected from 1710 (9.2.23071.136) to 3.26032.10.0 (excl.)

References

Problem Types