ZeroHour

CVE-2026-65818

mass

Critical SSRF Privilege Escalation in Microsoft Power Automate (Power Platform)

CVSS 3.1
9.9 critical
EPSS
<1%p27
Published
()
Modified
AI analysis

Server-side request forgery (CWE-918) in Microsoft Power Automate, part of Microsoft Power Platform, lets a low-privileged authenticated user cause the service to make network requests to internal or attacker-influenced endpoints. With network attack vector, low privileges required, no user interaction, and a changed scope with high confidentiality, integrity and availability impact (CVSS 9.9), the SSRF can be leveraged to reach internal services and elevate the attacker's privileges beyond their normal user role. Any organization whose tenants use Power Automate flows is exposed, since exploitation requires only a valid low-privilege account with network access to the service. There is no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS assigns a 0.3% 30-day exploitation probability (27th percentile), indicating limited near-term risk.

What to do: Verify remediation through Microsoft's MSRC advisory for CVE-2026-65818: the Power Automate cloud service is patched server-side, so confirm your tenant has received the update and patch any separately installed components (e.g., Power Automate Desktop or the on-premises data gateway) if the advisory lists them as affected. Review Power Automate flow and connector permissions and DLP policies, and monitor for unexpected privilege changes or anomalous outbound requests from the service. With no public PoC, KEV listing, or known exploitation, standard prioritization within your normal patch cycle is reasonable.

Affected
microsoft Power Automate (Microsoft Power Platform)
Estimated exposure
massmillions of users (Power Automate spans millions of monthly active users within Microsoft 365/Dynamics 365 estates) — Power Automate is a core Power Platform cloud service that Microsoft has publicly reported with millions of monthly active users, so the potentially vulnerable cloud footprint is at the multi-million-user scale; the number of tenants…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
power platform
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.