PT-2026-3325 · Microsoft · Power Apps

Alasdair Gorniak

·

Published

2026-01-16

·

Updated

2026-02-12

·

CVE-2026-20960

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Power Apps (affected versions not specified)
Description An improper authorization issue exists in Microsoft Power Apps. This allows an authorized attacker to execute code over a network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-20960

Affected Products

Power Apps