CVE-2026-65818
massCritical SSRF Privilege Escalation in Microsoft Power Automate (Power Platform)
Server-side request forgery (CWE-918) in Microsoft Power Automate, part of Microsoft Power Platform, lets a low-privileged authenticated user cause the service to make network requests to internal or attacker-influenced endpoints. With network attack vector, low privileges required, no user interaction, and a changed scope with high confidentiality, integrity and availability impact (CVSS 9.9), the SSRF can be leveraged to reach internal services and elevate the attacker's privileges beyond their normal user role. Any organization whose tenants use Power Automate flows is exposed, since exploitation requires only a valid low-privilege account with network access to the service. There is no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS assigns a 0.3% 30-day exploitation probability (27th percentile), indicating limited near-term risk.
What to do: Verify remediation through Microsoft's MSRC advisory for CVE-2026-65818: the Power Automate cloud service is patched server-side, so confirm your tenant has received the update and patch any separately installed components (e.g., Power Automate Desktop or the on-premises data gateway) if the advisory lists them as affected. Review Power Automate flow and connector permissions and DLP policies, and monitor for unexpected privilege changes or anomalous outbound requests from the service. With no public PoC, KEV listing, or known exploitation, standard prioritization within your normal patch cycle is reasonable.
| microsoft Power Automate (Microsoft Power Platform) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- power platform
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.