Product
microsoft power automate for desktop
4 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-40374
CVE-2025-47966
CVE-2025-29817
CVE-2025-21187
< 2.67
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information
all versions
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges
< 2.51.349.24355
Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
>= 2.46 and < 2.46.184.25013
Microsoft Power Automate Remote Code Execution Vulnerability