CVE-2026-65818: Power Automate Elevation of Privilege Vulnerability
Power Automate Elevation of Privilege Vulnerability
Other sources
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized to use Power Automate and must be able to reach the affected service over a network. No user interaction is required.
What is the potential impact of successful exploitation?
Successful exploitation can allow the authorized attacker to elevate privileges. The supplied severity vector indicates potential high impact to confidentiality, integrity, and availability, including impact beyond the initially affected security authority.
Is exploitation considered straightforward?
The attack complexity is rated high, indicating exploitation requires conditions beyond simply sending a basic network request. The available data does not identify those required conditions.