AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-59118

CRITICAL · CVSS 9.3 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Microsoft Power Apps is vulnerable due to improper authorization, enabling unauthorized attackers to elevate their privileges over a network. This critical flaw poses a significant risk of unauthorized access and potential data breaches, making it imperative for organizations using Power Apps to prioritize immediate remediation efforts. Security teams and system administrators should address this vulnerability to safeguard their applications and sensitive data.

CVE
CVE-2026-59118
Severity
CRITICAL
CVSS
9.3
EPSS
0.39%

Original NVD Description

Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)