CVE-2026-77897

Summary

Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.

Affected Software

VendorProductVersion RangeStatus
MicrosoftPower Automate agent for virtual desktops1.0.0.0 < 2.71.115.26224affected
MicrosoftPower Automate for Desktop1.0.0.0 < 2.71.115.26224affected

Weaknesses

  • CWE-23: CWE-23: Relative Path Traversal

References