Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-20960

Опубликовано: 16 янв. 2026
Источник: msrc
CVSS3: 8
EPSS Низкий

Описание

Microsoft Power Apps Remote Code Execution Vulnerability

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

FAQ

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?

Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.

According to the CVSS metric, the attack vector is network (AV:N) and user interaction is required (UI:R). What is the target context of the remote code execution? This attack requires a user to open a specially crafted shared app from the attacker to initiate remote code execution.

Обновления

ПродуктСтатьяОбновление
Microsoft Power Apps

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 17%
0.00054
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
18 дней назад

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

CVSS3: 8
github
18 дней назад

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

EPSS

Процентиль: 17%
0.00054
Низкий

8 High

CVSS3