Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
History

Thu, 29 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Title Microsoft Power Apps Remote Code Execution Vulnerability PowerApps Desktop Client Remote Code Execution Vulnerability
First Time appeared Microsoft power Apps Desktop Client
CPEs cpe:2.3:a:microsoft:power-apps:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:power_apps_desktop_client:*:*:*:*:*:*:*:*
Vendors & Products Microsoft power-apps
Microsoft power Apps Desktop Client

Fri, 16 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 21:45:00 +0000

Type Values Removed Values Added
Description Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Title Microsoft Power Apps Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft power-apps
Weaknesses CWE-285
CPEs cpe:2.3:a:microsoft:power-apps:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft power-apps
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published: 2026-01-16T21:28:10.895Z

Updated: 2026-01-30T03:40:08.654Z

Reserved: 2025-12-04T20:04:16.340Z

Link: CVE-2026-20960

cve-icon Vulnrichment

Updated: 2026-01-16T21:49:26.640Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-16T22:16:25.553

Modified: 2026-01-26T15:05:39.840

Link: CVE-2026-20960

cve-icon Redhat

No data.