Executive brief
Microsoft Power Automate, a service used to automate workflows between apps and services, contains a vulnerability that could allow an authorized user to access sensitive information they are not permitted to see. An attacker with basic user permissions could exploit this over the network to disclose internal data. This could lead to the exposure of confidential business logic or organizational data, potentially aiding further attacks.
Technical details
An information disclosure vulnerability (CWE-200) exists in Microsoft Power Automate. The flaw allows an authenticated attacker with low privileges to disclose sensitive information over a network. According to the CVSS vector, the attack vector is network-based, complexity is low, and no user interaction is required, though it does require 'Low' prior authentication. Successful exploitation results in a 'High' impact on confidentiality, while integrity and availability remain unaffected. Users should refer to the Microsoft Security Response Center for specific patching or mitigation guidance.
Affected products
- Microsoft Power Automate
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory