← All Advisories

CVE-2026-26149

Status: UPDATED  |  Advisory ID: CVE-2026-26149

Key Details

CVECVE-2026-26149
CVSSCVSS 9.0 (Critical).
Affected productsMicrosoft power_apps
Classified asCWE-150 (Improper Neutralization of Escape, Meta, or Control Sequences)

What to Know

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-26149
Vendor advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26149