CVE-2026-77897
massLocal Privilege Escalation via Relative Path Traversal in Microsoft Power Automate
CVE-2026-77897 is a relative path traversal flaw (CWE-23) in Microsoft Power Automate that allows an authorized attacker to elevate privileges locally. To trigger it, an attacker who already holds low-privilege authorized access on a local system must exploit the traversal under high-complexity conditions, with no user interaction required. Successful exploitation results in local privilege elevation with high impact on the confidentiality, integrity, and availability of the affected system. Any organization or user running Power Automate is potentially affected, though the local, low-privilege attack requirement limits practical exposure to environments where such access exists. No public proof-of-concept or in-the-wild exploitation is known; the flaw is not in CISA KEV and EPSS estimates only a ~0.3% probability of exploitation in the next 30 days.
What to do: Track Microsoft's advisory for CVE-2026-77897 and apply the latest Power Automate / Power Automate Desktop security update as soon as affected and fixed builds are published, since no specific version numbers are provided in the available data. Meanwhile, minimize the number of low-privilege local accounts on sensitive Windows hosts, because exploitation requires existing authorized local access. Given the low EPSS (0.3%) and absence of a public PoC, this is a routine patch-cycle item rather than an emergency.
| Microsoft Power Automate | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-23
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.