CVE-2026-32172

8.0

Microsoft · Power Apps

An uncontrolled search path element vulnerability in Microsoft Power Apps allows a remote, unauthorized attacker to execute arbitrary code.

Executive summary

This high-severity vulnerability in Microsoft Power Apps permits unauthorized remote code execution, posing a significant risk to organizational integrity.

Vulnerability

The flaw is an uncontrolled search path element (CWE-427) that allows an unauthenticated, remote attacker to manipulate the execution environment. This permits the execution of arbitrary code when triggered by a user interaction, as indicated by the CVSS vector.

Business impact

The potential for remote code execution represents a critical threat to the confidentiality and integrity of the affected environment. With a CVSS score of 8.0, this vulnerability could allow an attacker to gain unauthorized control over application processes, potentially leading to data exfiltration or lateral movement within the network.

Remediation

Immediate Action: Review the Microsoft Security Response Center (MSRC) update guide for CVE-2026-32172 and apply all recommended security patches as soon as they become available.

Proactive Monitoring: Monitor network traffic and server logs for unusual process execution patterns or suspicious attempts to access unauthorized search paths.

Compensating Controls: Implement strict endpoint security policies and utilize application control solutions to restrict the execution of unauthorized binaries or scripts within the Power Apps environment.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high impact of remote code execution, security teams should prioritize monitoring official Microsoft advisory channels for the release of specific patches. Once a patch is released, it must be deployed immediately to mitigate the risk of exploitation. Until then, ensure that least privilege principles are enforced across all service accounts managing Power Apps.

More Microsoft CVEs

Sources