Overview
What is CVE-2026-26149?
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.
Vulnerability intelligence
CVE-2026-26149 and is rated Critical severity with a CVSS score of 9.0. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.