Junglewise Threat Intelligence

CVE-2026-24301: Microsoft Copilot command injection

CVE-2026-24301 · Severity: high · CVSS 8.8 · Published 2026-08-18

Vendors: Microsoft.

Executive brief

Microsoft Copilot is an AI assistant used to help with productivity tasks. An attacker can exploit a command injection vulnerability to send specially crafted commands that bypass security controls and extract sensitive information across the network without authentication.

Technical details

This is a command injection vulnerability (CWE-77/78) in Microsoft Copilot caused by improper neutralization of special elements in user-supplied input. The vulnerability allows an unauthenticated attacker with network access to inject malicious commands that are executed by the application, leading to unauthorized information disclosure. No special privileges or user interaction is required to trigger the flaw. A patch is available from Microsoft; users should apply the latest security update.

Affected products

  • Microsoft Copilot

Timeline

  • 2026-08-18: disclosed

References