CVE-2026-32172
Published Apr 23, 2026Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
6 CVEs tagged to microsoft / power_apps — 2 Critical, 2 High, 1 Medium, 1 Low, 0 Unrated.
Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network
Microsoft Power Apps (online) Spoofing Vulnerability
Microsoft Power Apps Spoofing Vulnerability