Executive brief
Power Automate is Microsoft's cloud-based workflow automation platform used by organizations to connect apps and automate business processes. A server-side request forgery vulnerability allows an authorized user to make unauthorized network requests through the Power Automate service, potentially enabling them to access internal resources or escalate their privileges beyond their intended scope.
Technical details
A server-side request forgery (SSRF) vulnerability in Microsoft Power Automate permits an authenticated attacker to send crafted requests that cause the service to make unintended network connections on the attacker's behalf. The vulnerability requires prior authentication and network access to Power Automate. Successful exploitation enables privilege escalation, allowing an attacker to access restricted resources or perform actions beyond their authorization level. Microsoft has published a security update to address this issue.
Affected products
- Microsoft Power Automate
Timeline
- 2026-09-03: disclosed