CVE-2026-26129
7.5Infor · M365 Copilot
Improper neutralization of special elements in M365 Copilot allows an unauthorized attacker to disclose sensitive information over a network.
Executive summary
A command injection vulnerability in M365 Copilot allows unauthorized attackers to disclose network information, presenting a high risk to data confidentiality.
Vulnerability
This is a command injection flaw categorized under CWE-138, triggered by improper neutralization of special elements. The attack vector is network based and requires no user interaction or authentication.
Business impact
A successful exploit permits unauthorized network access to sensitive data, leading to potential information disclosure and loss of data confidentiality. Although the CVSS score is 7.5, the absence of required authentication or user interaction makes this flaw easily exploitable at scale.
Remediation
Immediate Action: Apply vendor security updates immediately as detailed in the Microsoft Security Response Center advisory.
Proactive Monitoring: Monitor network traffic for unusual data exfiltration patterns and review administrative access logs.
Compensating Controls: Implement network segmentation and egress filtering to limit potential data exposure in the event of an exploit.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability demands urgent attention due to its lack of authentication requirements and remote attack vector. Security teams must apply available vendor patches immediately and monitor systems for abnormal network behavior to protect sensitive assets.
More Infor CVEs
Sources
- M365 Copilot Information Disclosure Vulnerability Vendor advisory