Path traversal in Power Automate agent for virtual desktops and Power Automate for Desktop - CVE-2026-77897

 

Path traversal in Power Automate agent for virtual desktops and Power Automate for Desktop - CVE-2026-77897

Published: September 8, 2026


Vulnerability identifier: #VU147746
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-77897
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in Microsoft Power Automate Desktop. A local user can send a specially crafted HTTP request and read arbitrary files on the system, leading to privilege escalation.


Affected software

Power Automate agent for virtual desktops
Power Automate for Desktop

How to mitigate CVE-2026-77897

Install updates from vendor's website.

Power Automate agent for virtual desktops - update to 2.71.115.26224
Power Automate for Desktop - update to 2.71.115.26224

External References

Related Security Bulletins