CVE-2026-65818
Microsoft · Microsoft Power Platform
A Server-Side Request Forgery vulnerability in Microsoft Power Automate allows an authenticated attacker to elevate privileges over a network.
Executive summary
An authenticated privilege escalation vulnerability in Microsoft Power Automate poses a significant risk to organizational data integrity and system control.
Vulnerability
This vulnerability is a Server-Side Request Forgery (CWE-918) that allows an authenticated attacker to perform actions outside of their authorized scope. By exploiting this flaw, an attacker can manipulate requests to elevate their privileges within the network environment.
Business impact
With a CVSS score of 8.5, this vulnerability represents a high risk to business operations. Successful exploitation allows for privilege escalation, which could grant attackers unauthorized access to sensitive internal resources, potentially leading to widespread data breaches or administrative takeover of the affected Power Automate workflows.
Remediation
Immediate Action: Review the Microsoft Security Response Center update guide for CVE-2026-65818 and apply all relevant security patches or configuration changes provided by Microsoft.
Proactive Monitoring: Monitor service logs for anomalous outgoing requests originating from Power Automate components that deviate from established behavioral baselines.
Compensating Controls: Implement strict identity and access management policies and review the scope of permissions granted to users within the Power Platform to minimize the blast radius of a potential compromise.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations should immediately consult the Microsoft Security Update Guide to determine if their specific environment is impacted. Given the potential for privilege escalation, patching or applying mitigating configuration changes is essential to maintain the security posture of the Power Platform environment.
More Microsoft CVEs
Sources
- Power Automate Elevation of Privilege Vulnerability Vendor advisory