Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.

Project Subscriptions

Vendors Products
Microsoft Subscribe
Power-apps Subscribe
Power Apps Subscribe
Power Apps Desktop Client Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 07 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft power Apps
CPEs cpe:2.3:a:microsoft:power_apps:*:*:*:*:*:windows:*:*
Vendors & Products Microsoft power Apps

Mon, 27 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Title Microsoft Power Apps Spoofing Vulnerability Microsoft Power Apps Desktop Client Spoofing Vulnerability
First Time appeared Microsoft power Apps Desktop Client
CPEs cpe:2.3:a:microsoft:power-apps:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:power_apps_desktop_client:*:*:*:*:*:*:*:*
Vendors & Products Microsoft power Apps Desktop Client

Mon, 20 Apr 2026 21:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to bypass a security feature over a network. Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.
Title Microsoft Power Apps Security Feature Bypass Microsoft Power Apps Spoofing Vulnerability

Tue, 14 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to bypass a security feature over a network.
Title Microsoft Power Apps Security Feature Bypass
First Time appeared Microsoft
Microsoft power-apps
Weaknesses CWE-150
CPEs cpe:2.3:a:microsoft:power-apps:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft power-apps
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H/E:U/RL:T/RC:C'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-05-12T17:37:53.609Z

Reserved: 2026-02-11T16:24:51.135Z

Link: CVE-2026-26149

cve-icon Vulnrichment

Updated: 2026-04-14T17:58:31.045Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-14T18:16:45.790

Modified: 2026-05-07T20:06:17.310

Link: CVE-2026-26149

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T00:15:16Z

Weaknesses