logo

Microsoft Power Pages misconfigurations exposing sensitive data

ID: 21be1679-3cfd-502a-87a6-9829f2de3791

STIX ID: report--21be1679-3cfd-502a-87a6-9829f2de3791

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-11-15

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Research from AppOmni (Aaron Costello) found that misconfigurations in Microsoft Power Pages—such as granting global table access, allowing public registration that confers elevated "authenticated user" permissions, and not enabling column-level masking—have exposed millions of records (including a reported NHS leak of 1.1 million employees' PII). The issue stems from layered access-control complexity and skipped security steps; a PoC using an intercepting proxy (Burp Suite) shows how exposed tables and sensitive columns can be enumerated, and AppOmni recommends removing excessive external access and tightening table/column permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.