Known vulnerabilities in Power Automate for Desktop
Vendor:
Microsoft
Software:
Power Automate for Desktop
Software CPE:
cpe:2.3:a:microsoft:power_automate_for_desktop:*:*:*:*:*:*:*:*
Website:
https://www.microsoft.com
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU131256 - Exposure of sensitive information to an unauthorized actor CVE-2026-40374 |
CWE-200 | Medium | 2.67 | 12.05.2026 |
SB20260512117 |
||
| #VU110757 - Exposure of sensitive information to an unauthorized actor CVE-2025-47966 |
CWE-200 | High | - | 10.06.2025 |
SB2025061098 |
||
| #VU107572 - Uncontrolled Search Path Element CVE-2025-29817 |
CWE-427 | Medium | 2.51.349.24355 | 17.04.2025 |
SB2025041722 |
||
| #VU102693 - Improper Control of Generation of Code ('Code Injection') CVE-2025-21187 |
CWE-94 | High | - | 14.01.2025 |
SB2025011468 |
||
| #VU97108 - Improper Access Control CVE-2024-43479 |
CWE-284 | Medium | - | 10.09.2024 |
SB20240910145 |