CVE-2026-26133
7.1Microsoft · Microsoft 365 Copilot, Edge, and Excel
An AI command injection vulnerability in M365 Copilot allows an unauthenticated attacker to disclose sensitive information over a network.
Executive summary
A critical AI command injection vulnerability in Microsoft 365 Copilot and associated mobile applications allows unauthorized information disclosure, posing a significant risk to data confidentiality.
Vulnerability
The flaw is categorized as an improper neutralization of special elements used in a command (CWE-77). It permits an unauthenticated attacker to inject malicious commands into the AI interface, resulting in unauthorized data exposure.
Business impact
Successful exploitation allows unauthorized entities to gain access to sensitive information processed by M365 Copilot. Given the CVSS score of 7.1, this represents a high-severity risk that could lead to significant data breaches, violation of privacy regulations, and potential loss of proprietary business intelligence.
Remediation
Immediate Action: Update all affected Microsoft 365 Copilot, Edge, and Excel applications on Android and iOS devices to the latest versions provided in the Microsoft Security Update Guide.
Proactive Monitoring: Review enterprise mobile management (EMM) logs for unusual application behavior and monitor network traffic for unexpected data exfiltration patterns originating from mobile endpoints.
Compensating Controls: Implement strict mobile device management (MDM) policies to restrict app permissions and enforce network-level filtering to prevent unauthorized outbound connections from compromised applications.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this vulnerability necessitates immediate action to secure mobile environments. Organizations should prioritize updating all instances of the affected Microsoft applications to the remediated versions to neutralize the risk of AI command injection and potential data disclosure.
More Microsoft CVEs
Sources
- M365 Copilot Information Disclosure Vulnerability Vendor advisory