Executive brief
Power Automate is Microsoft's cloud-based workflow automation platform used by enterprises to streamline business processes. A path traversal vulnerability allows an authorized user to access files and directories outside intended locations, potentially leading to unauthorized privilege escalation and access to sensitive system data.
Technical details
The vulnerability is a relative path traversal flaw in Power Automate that permits an authenticated attacker to manipulate file paths using directory traversal sequences (e.g., ../) to access restricted resources and escalate privileges locally. The attack requires valid credentials and local access to the system. Successful exploitation could allow an attacker to read or modify sensitive files, escalate from a standard user to administrative privileges, or execute arbitrary code. Microsoft has released security patches to address this issue.
Affected products
- Microsoft Power Automate
Timeline
- 2026-09-08: disclosed