ZeroHour

CVE-2026-77897

mass

Local Privilege Escalation via Relative Path Traversal in Microsoft Power Automate

CVSS 3.1
7.0 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-77897 is a relative path traversal flaw (CWE-23) in Microsoft Power Automate that allows an authorized attacker to elevate privileges locally. To trigger it, an attacker who already holds low-privilege authorized access on a local system must exploit the traversal under high-complexity conditions, with no user interaction required. Successful exploitation results in local privilege elevation with high impact on the confidentiality, integrity, and availability of the affected system. Any organization or user running Power Automate is potentially affected, though the local, low-privilege attack requirement limits practical exposure to environments where such access exists. No public proof-of-concept or in-the-wild exploitation is known; the flaw is not in CISA KEV and EPSS estimates only a ~0.3% probability of exploitation in the next 30 days.

What to do: Track Microsoft's advisory for CVE-2026-77897 and apply the latest Power Automate / Power Automate Desktop security update as soon as affected and fixed builds are published, since no specific version numbers are provided in the available data. Meanwhile, minimize the number of low-privilege local accounts on sensitive Windows hosts, because exploitation requires existing authorized local access. Given the low EPSS (0.3%) and absence of a public PoC, this is a routine patch-cycle item rather than an emergency.

Affected
Microsoft Power Automate
Estimated exposure
masspotentially millions of users/endpoints (Power Automate is bundled with Microsoft 365 commercial plans and Power Automate Desktop ships with Windows 10/11) — Order-of-magnitude estimate based on Microsoft's distribution model: Power Automate is included in Microsoft 365 commercial licensing (hundreds of millions of seats) and Power Automate Desktop has been bundled with Windows 10/11, so a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.

Weakness
CWE-23
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.