Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 08 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally. | |
| Title | Microsoft Power Automate Desktop Elevation of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft power Automate Agent For Virtual Desktops Microsoft power Automate For Desktop |
|
| Weaknesses | CWE-23 | |
| CPEs | cpe:2.3:a:microsoft:power_automate_agent_for_virtual_desktops:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:power_automate_for_desktop:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft power Automate Agent For Virtual Desktops Microsoft power Automate For Desktop |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-09-08T18:39:22.916Z
Reserved: 2026-08-21T17:26:55.612Z
Link: CVE-2026-77897
No data.
Status : Awaiting Analysis
Published: 2026-09-08T18:20:39.850
Modified: 2026-09-08T18:40:14.483
Link: CVE-2026-77897
No data.
OpenCVE Enrichment
No data.
Weaknesses