Junglewise Threat Intelligence

CVE-2026-77897: Microsoft Power Automate relative path traversal privilege escalation

CVE-2026-77897 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Power Automate is Microsoft's cloud-based workflow automation platform used by enterprises to streamline business processes. A path traversal vulnerability allows an authorized user to access files and directories outside intended locations, potentially leading to unauthorized privilege escalation and access to sensitive system data.

Technical details

The vulnerability is a relative path traversal flaw in Power Automate that permits an authenticated attacker to manipulate file paths using directory traversal sequences (e.g., ../) to access restricted resources and escalate privileges locally. The attack requires valid credentials and local access to the system. Successful exploitation could allow an attacker to read or modify sensitive files, escalate from a standard user to administrative privileges, or execute arbitrary code. Microsoft has released security patches to address this issue.

Affected products

  • Microsoft Power Automate

Timeline

  • 2026-09-08: disclosed

References

Related threats