Junglewise Threat Intelligence

CVE-2026-40374: Microsoft Power Automate Information Disclosure

CVE-2026-40374 · Severity: medium · CVSS 6.5 · Published 2026-05-12

Executive brief

Microsoft Power Automate, a service used to automate workflows between apps and services, contains a vulnerability that could allow an authorized user to access sensitive information they are not permitted to see. An attacker with basic user permissions could exploit this over the network to disclose internal data. This could lead to the exposure of confidential business logic or organizational data, potentially aiding further attacks.

Technical details

An information disclosure vulnerability (CWE-200) exists in Microsoft Power Automate. The flaw allows an authenticated attacker with low privileges to disclose sensitive information over a network. According to the CVSS vector, the attack vector is network-based, complexity is low, and no user interaction is required, though it does require 'Low' prior authentication. Successful exploitation results in a 'High' impact on confidentiality, while integrity and availability remain unaffected. Users should refer to the Microsoft Security Response Center for specific patching or mitigation guidance.

Affected products

  • Microsoft Power Automate

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats