CVE-2026-26164
7.5Microsoft · M365 Copilot
An improper neutralization vulnerability in Microsoft M365 Copilot allows unauthorized attackers to achieve information disclosure over a network.
Executive summary
An information disclosure vulnerability in Microsoft M365 Copilot allows unauthenticated attackers to access sensitive data over the network via command injection.
Vulnerability
This is an improper neutralization of special elements in a command, categorized as CWE-74. The vulnerability can be exploited remotely by an unauthenticated attacker over the network without requiring any user interaction.
Business impact
A successful exploit permits unauthorized external actors to view sensitive organizational data processed or stored within Microsoft 365 Copilot Business Chat. Given the CVSS score of 7.5, this high severity flaw threatens data confidentiality and can lead to severe regulatory and compliance violations if proprietary or personally identifiable information is exposed.
Remediation
Immediate Action: Apply the official security updates provided by Microsoft through the Microsoft Security Response Center as soon as possible.
Proactive Monitoring: Monitor network and application logs for unusual query patterns or unexpected data retrieval requests targeting Copilot endpoints.
Compensating Controls: Implement strict network perimeter controls and utilize Web Application Filters where applicable to inspect traffic destined for Copilot integrations.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Microsoft 365 Copilot must treat this high severity vulnerability with urgency. Administrators should immediately check the Microsoft advisory portal for patch availability and apply the necessary updates to prevent potential unauthorized information disclosure.
More Microsoft CVEs
Sources
- M365 Copilot Information Disclosure Vulnerability Vendor advisory