Path traversal in Power Automate agent for virtual desktops and Power Automate for Desktop - CVE-2026-77897
Published: September 8, 2026
Vulnerability details
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in Microsoft Power Automate Desktop. A local user can send a specially crafted HTTP request and read arbitrary files on the system, leading to privilege escalation.
Affected software
Power Automate for Desktop
How to mitigate CVE-2026-77897
Power Automate for Desktop - update to 2.71.115.26224