Executive brief
Microsoft Power Pages, a platform used for creating and hosting external-facing business websites, contains a critical security flaw. An unauthorized attacker can remotely execute malicious commands on the system over the internet. This could lead to a total compromise of the service, including the theft of sensitive customer data and the disruption of hosted business websites.
Technical details
A command injection vulnerability (CWE-77) exists in Microsoft Power Pages due to the improper neutralization of special elements used in a command. The flaw allows an unauthenticated attacker to send specially crafted requests over the network to execute arbitrary code on the underlying infrastructure. With a CVSS score of 10.0, the attack requires no user interaction and no prior privileges. Successful exploitation results in a full compromise of confidentiality, integrity, and availability, with the impact extending beyond the immediate security scope of the affected component.
Affected products
- Microsoft Power Pages
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory