CVE-2026-77897HighCVSS 7.0
Microsoft Power Automate Desktop Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
🎯 Affected products2
- Power Automate agent for virtual desktops
- Power Automate for Desktop
✅ Remediation
KBRelease Notes (Security Update) — fixed build 2.71.115.26224