Microsoft Power Automate Desktop Information Disclosure Vulnerability

Vulnerability

A vulnerability in Power Automate Desktop allows an authorized attacker to disclose sensitive information over the network. This issue arises from a logging problem that causes values stored in variables marked as 'Sensitive' within Power Automate Desktop flows to potentially appear in execution logs. These logs can be accessed by users with Owner, Co-Owner, or Runner permissions for the affected desktop flow.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information, specifically values from variables designated as 'Sensitive' in Power Automate Desktop flows. These values may be included in execution logs uploaded to the Power Automate portal, where they can be viewed by users with appropriate permissions.

Remediation

Users can download the security update for Power Automate for Desktop from the Microsoft Update Catalog. Instructions for applying the update are available in the release notes.

Added: May 12, 2026, 7:39 PM
Updated: May 12, 2026, 7:39 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
2.5
exploitability
3.3
remediation
7.7
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.