Junglewise Threat Intelligence

CVE-2026-23652: Microsoft Power Pages command injection

CVE-2026-23652 · Severity: critical · CVSS 10 · Published 2026-05-22

Vendors: Microsoft.

Executive brief

Microsoft Power Pages, a platform used for creating and hosting external-facing business websites, contains a critical security flaw. An unauthorized attacker can remotely execute malicious commands on the system over the internet. This could lead to a total compromise of the service, including the theft of sensitive customer data and the disruption of hosted business websites.

Technical details

A command injection vulnerability (CWE-77) exists in Microsoft Power Pages due to the improper neutralization of special elements used in a command. The flaw allows an unauthenticated attacker to send specially crafted requests over the network to execute arbitrary code on the underlying infrastructure. With a CVSS score of 10.0, the attack requires no user interaction and no prior privileges. Successful exploitation results in a full compromise of confidentiality, integrity, and availability, with the impact extending beyond the immediate security scope of the affected component.

Affected products

  • Microsoft Power Pages

Timeline

  • 2026-05-22: disclosed
  • 2026-05-22: advisory

References

Related threats