Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17028 | Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. |
Fri, 13 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:power_automate_for_desktop:*:*:*:*:*:*:*:* |
Tue, 08 Jul 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft power Automate For Desktop |
|
| CPEs | cpe:2.3:a:microsoft:power_automate_for_desktop:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft power Automate For Desktop |
Fri, 06 Jun 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Jun 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. | |
| Title | Power Automate Elevation of Privilege Vulnerability | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-02-26T17:51:07.229Z
Reserved: 2025-05-14T14:13:13.465Z
Link: CVE-2025-47966
Updated: 2025-06-06T13:08:47.879Z
Status : Analyzed
Published: 2025-06-05T21:15:22.127
Modified: 2025-07-08T16:26:34.813
Link: CVE-2025-47966
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:51:38Z
EUVD