CVE-2026-26149Disclosure(microsoft / power_apps)

LOWCVSS 9.0 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-150

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • power_apps

Threat summary

  • 11 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • General: 4 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-17); latest day: 4
  • 11 total mentions across 4 days

Affected systems

Vendors
Products
power_apps

Deep dive

Activity timeline11 mentions / 4d
01234Mentions · 2026-04-14: 2Mentions · 2026-04-17: 4Mentions · 2026-04-30: 1Mentions · 2026-05-11: 4Technical Details · 2026-04-14: 1Technical Details · 2026-04-17: 4Technical Details · 2026-04-30: 1Technical Details · 2026-05-11: 304-1404-1704-3005-11
Signal classification2 categories
Disclosure
763.6%
General
436.4%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure1General1
2026-04-174
Disclosure2General2
2026-04-301
Disclosure1
2026-05-114
Disclosure3General1
Full discourse11 posts
  • Horizon Secured@horizon_secured
    General

    🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗔𝗽𝗿𝗶𝗹 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 This month brings 2 Zero-Days and 2 additional 9.0+ vulnerabilities. 𝗠𝗮𝗶𝗻 𝗶𝘀𝘀𝘂𝗲𝘀 𝘁𝗼 𝘄𝗮𝘁𝗰𝗵: • CVE-2026-33825 – Microsoft Defender EoP (BlueHammer) • CVE-2026-32201 – SharePoint spoofing • CVE-2026-33824 – Windows IKE RCE • CVE-2026-26149 – Power Apps security bypass Full breakdown in this month’s Horizon Alert. #PatchTuesday #CyberSecurity #ZeroDay #Vulnerability #Microsoft

    Post summary

    The alert enumerates four CVEs with brief vulnerability descriptors but offers no evidence of exploitation, PoC, or patch details.

    010911.2K
    2.5K followersView on X
  • z3n@zench4n
    General

    Recent CVEs highlight the danger of broken access control and injection. CVE-2026-26149 in Microsoft Power Apps shows how improper neutralization can bypass auth. For AI agents, a similar flaw in a connected plugin means an agent could execute arbitrary logic.

    Post summary

    The post references CVE-2026-26149 in Microsoft Power Apps, highlighting improper neutralization that can bypass auth and hinting at analogous flaws in AI agents, but provides no PoC, exploit, patch, or active exploitation details.

    1001057
    1.5K followersView on X
  • z3n@zench4n
    General

    Watch for vulnerabilities in the integration layer. CVE-2026-26149 in Power Apps shows how improper neutralization can lead to auth bypass. For AI agents, a similar flaw in a tool-calling function means an attacker controls the agent's environment.

    Post summary

    The message highlights the existence of CVE-2026-26149 in Power Apps and notes basic flaw details, but offers no PoC, exploit code, active exploitation evidence, or remediation.

    100003
    1.5K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-26149-microsoft-power-apps #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The message only provides a link and hashtags, offering no concrete information about the CVE.

    0000016
    188 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-26149 CVSS: 9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a…

    Post summary

    The advisory announces a critical Microsoft Power Apps vulnerability (CVE‑2026‑26149) with high severity, but does not provide PoC, exploit, or patch details.

    0000042
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-26149 CVSS: 9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces CVE-2026-26149 with a high CVSS score and critical severity but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000039
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-26149 (CVSS 9) — microsoft power apps. CVE: CVE-2026-26149 CVSS: 9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post alerts to CVE-2026-26149, stating its critical severity and CVSS score, but offers no further technical description, PoC, exploit code, or patch details.

    0000028
    197 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-26149 | Microsoft Power Apps Desktop Client Spoofing Vulnerability https://www.aakashrahsi.online/post/cve-2026-26149 https://t.co/QFOUbyty86

    Post summary

    The post announces Microsoft Power Apps Desktop Client Spoofing Vulnerability (CVE-2026-26149) and includes links to a blog post detailing it.

    0000018
    1 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26149 Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to bypass a security feature over a network. https://www.cve.org/CVERecord?id=CVE-2026-26149 ----- Traducción: CVE-2026-26149 Neutralizac… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-26149, describing it as an improper neutralization that lets an authorized attacker bypass a Microsoft Power Apps security feature via a network. No further details on exploitation or mitigation are provided.

    0000032
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26149 Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to bypass a security feature over a network. https://www.cve.org/CVERecord?id=CVE-2026-26149

    Post summary

    The text reports CVE-2026-26149, detailing a flaw in Microsoft Power Apps that permits an authorized network attacker to bypass a security feature, without providing PoC, exploit code, or patch information.

    00000185
    57.2K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 UI:R CVE in Power Apps: so it’s not “remote takeover,” it’s “please click the thing” o’clock. At least Microsoft admitted trust abuse needs user help… unlike us. https://windowsforum.com/threads/cve-2026-26149-power-apps-risk-user-assisted-trust-abuse-explained.412737/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #EnterpriseSecurity #PowerApps #PhishingDefense #Cve202626149

    Post summary

    The forum post references CVE‑2026‑26149 in Power Apps, indicating it is a user‑assisted trust abuse flaw rather than a remote takeover, but offers no exploitation details, patch information, or technical specifics.

    0000033
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftpower_apps-windows-

Explore more