Microsoft has submitted CVE-2026-59118, a critical (CVSS 9.3) improper authorization flaw in Microsoft Power Apps that allows an unauthorized attacker to elevate privileges over a network. The record has only just entered NVD and has not yet been analyzed, so the details below reflect Microsoft's submission rather than a finalized NVD entry.
What Is It
CVE-2026-59118 is an improper authorization vulnerability (CWE-285) in Microsoft Power Apps. Per Microsoft's description, the flaw "allows an unauthorized attacker to elevate privileges over a network."
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N, scoring 9.3 (CRITICAL). Broken down: the attack is network-reachable, low complexity, and requires no privileges, but it does require user interaction. Critically, scope is Changed, meaning a successful attack impacts resources beyond the vulnerable component's security authority. Confidentiality and integrity impact are both High; availability is unaffected.
Why It Matters
The combination of no required privileges, low attack complexity, and changed scope is what drives this into critical territory. No technical details of an exploitation path have been published, but the vector metrics imply a scenario along these lines: an attacker with no prior access reaches the flaw across a network and, given a single user interaction, crosses the intended authorization boundary to gain elevated privileges with high confidentiality and integrity impact. That reading is inferred from the CVSS vector alone; Microsoft has not described the underlying mechanism, and the actual attack chain may differ.
Microsoft tagged the CVE exclusively-hosted-service, indicating the affected product is a cloud-hosted service rather than customer-deployed software.
No CISA KEV entry accompanies this record. There is no evidence of active exploitation in the supplied source material, and no KEV-mandated remediation deadline applies at this time.
What's Vulnerable
- Vendor: Microsoft
- Product: Microsoft Power Apps
- Affected versions: listed as
-(all / not version-scoped)
No CPE matches are present in the NVD record. Because Microsoft flagged this as an exclusively-hosted service, the record does not enumerate discrete customer-installable versions.
Patch Status
The NVD record is in Received status, submitted but not yet analyzed or enriched by NVD, with Microsoft ([email protected]) as the source identifier. The record carries a publication timestamp of 2026-08-07 UTC, which is ahead of this brief; scoring, CPE data, and references may all change once NVD completes analysis. The sole reference is the MSRC Update Guide entry for this CVE. No required-action deadline or remediation guidance beyond the MSRC advisory is present in the supplied data; consult the MSRC entry for Microsoft's current mitigation and fix status.
Sources
- NVD, CVE-2026-59118: https://nvd.nist.gov/vuln/detail/CVE-2026-59118
- Microsoft MSRC Update Guide; CVE-2026-59118: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59118