CVE-2026-59118Disclosure(microsoft / power_apps)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • power_apps

Threat summary

  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-08-07); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
power_apps

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-08-06: 1Mentions · 2026-08-07: 2Mentions · 2026-08-12: 1Mentions · 2026-08-21: 1Mentions · 2026-09-13: 1Technical Details · 2026-08-07: 2Technical Details · 2026-08-12: 1Technical Details · 2026-09-13: 108-0608-0708-1208-2109-13
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-061
Disclosure1
2026-08-072
Disclosure1General1
2026-08-121
General1
2026-08-211
Disclosure1
2026-09-131
Disclosure1
Full discourse6 posts
  • Intelligence, At Your Command.@TheAICommand
    Disclosure

    Two critical CVEs landed against managed AI agent services on 6 August 2026. There was nothing to patch. CVE-2026-62830, Azure SRE Agent: missing authorisation, CVSS 9.9, scope changed. CVE-2026-59118, Copilot Cowork: improper authorisation, 9.3. Both records state the vulnerability has already been fully mitigated by Microsoft and there is no action for users of the service to take. Neither was recorded as publicly disclosed or exploited at release. That is reassuring on likelihood. It is not an assurance that nothing happened in any given tenant, and the disclosure is not designed to answer that. Why it breaks the process: vulnerability management assumes a finding maps to an action. Give it a finding with no action and it either closes the record as not applicable, burying the only signal, or leaves it open forever and corrupts the ageing metric a board reads. The fix is a third disposition: recorded, no customer action available, routed to vendor assurance. Read as a series per provider, these disclosures are the closest thing to direct evidence of how a provider builds, tests and fixes. For an APRA-regulated entity, CPS 234 already covers it. Paragraph 16: assess the third party's information security capability. Paragraph 22: evaluate the design of its controls. Paragraph 28: where relying on its testing, assess whether it is commensurate with the standard's testing requirements. Then the part within reach. Microsoft's own documentation states that Conditional Access policies targeting all users do not include agents' user accounts, that a policy targeting agent identities does not apply to the agent's user account, and that an agent using an API key bypasses token issuance, so the policies do not apply. The vendor owns the code. The customer owns the blast radius.

    Post summary

    The text announces two critical CVEs affecting managed AI agent services, providing detailed technical information but noting that both have been fully mitigated by the vendor with no action required for users, and confirming no active exploitation or public PoC exists.

    10000105
    25 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft ■ 既存の脆弱性情報の更新 既存のマイクロソフトの脆弱性 1 件を更新 ・CVE-2026-59118 Copilot Cowork の特権の昇格の脆弱性 ■ 新規セキュリティ アドバイザリの公開 なし ■ 既存のセキュリティ アドバイザリの更新 なし

    Post summary

    The tweet reports an update of Microsoft CVE-2026-59118, labeling it a privilege‑escalation vulnerability, but provides no PoC, exploit, patch, or evidence of active exploitation.

    1000093
    90 followersView on X
  • Sebastien Gioria@SPoint
    Disclosure

    Copilot Cowork pouvait être détourné pour agir avec vos permissions M365, sans être authentifié https://blog.gioria.org/fr/ai/copilot-cowork-cve-2026-59118/?utm_source=twitter&utm_medium=post&utm_campaign=copilot-cowork-cve-2026-59118 #Microsoft365 #PatchTuesday

    Post summary

    The tweet announces CVE‑2026‑59118, indicating Microsoft Copilot Cowork could be hijacked to act with M365 permissions without authentication, but provides no PoC, active‑use, or patch details.

    00000121
    2.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59118 Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-59118 ----- Traducción: CVE-2026-59118 Autorización inapropiada en Microsoft Power Apps permit… http://infoflow.cloud`

    Post summary

    A tweet announcing CVE‑2026‑59118, describing improper authorization in Microsoft Power Apps that could allow privilege escalation, with no PoC, exploit code, or patches referenced.

    0000041
    98 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-59118 Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-59118

    Post summary

    The text only notes that CVE-2026-59118 is an improper authorization flaw in Microsoft Power Apps that could allow privilege escalation, with no further technical details, exploit evidence, or mitigation information.

    00000931
    57.9K followersView on X
  • Windows Forum@windowsforum
    Disclosure

    ⚠️ Microsoft disclosed a Power Apps elevation-of-privilege flaw with no patch, CVSS score, workaround, or affected-feature list. Admins get a warning—and a front-row seat to the cloud-service mystery. https://windowsforum.com/security-alerts.84/cve-2026-59118-power-apps-eop-has-no-customer-patch-yet.441868/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #CloudSecurity #PowerPlatform #PowerAppsSecurity https://t.co/ESElm3zi7h

    Post summary

    Microsoft has disclosed an elevation‑of‑privilege flaw in Power Apps (CVE‑2026‑59118) with no patch, CVSS score, or workaround currently available.

    0000058
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftpower_apps---

Explore more