PowerLift API key escalation exposed diagnostic logs and a potential RCE path

PowerLift collects diagnostic data from Outlook Mobile and other Microsoft applications. The researchers had a key for a development instance that appeared limited to uploading logs, but POST /api/tenant/settings/keys returned every existing key and its permissions. One active key had read, write, and Gym access, unlocking the rest of the tested API.
• Diagnostic archive access — /gym/combo/incidents listed uploaded incidents, while /gym/incidents/:id/files.zip returned their files. The sampled archives contained Microsoft employee email addresses, bearer tokens, Copilot chat data, and metadata for internal OneDrive and SharePoint files.
• Potential server-side code execution — /api/classifiers accepted JavaScript classifiers that could be enabled and run against the next incoming incident. importNamespace was available, indicating Jint with CLR interop. If System.Diagnostics.Process was exposed by the target configuration, System.Diagnostics.Process.Start() could launch a process on the server. The researchers stopped before creating a malicious classifier or executing a command, so this remained a technically supported RCE path rather than a completed proof.
The full-access key also exposed remedy management, including the go_to_url action shown in Outlook Mobile, and scrubber rules used to remove sensitive data from uploaded logs. Exploitation required a valid PowerLift API key for the development instance. Microsoft reported deploying a fix on May 6, 2026, but did not publish the patch details.
Vendors
Microsoft
Products
Clr
Copilot
Jint
Onedrive
Outlook Mobile
Powerlift
More