Junglewise Threat Intelligence

CVE-2026-26129: Microsoft M365 Copilot command injection

CVE-2026-26129 · Severity: high · CVSS 7.5 · Published 2026-05-07

Vendors: Microsoft.

Executive brief

Microsoft 365 Copilot, an AI-powered productivity tool, contains a vulnerability that could allow an unauthorized person to access sensitive information. By sending specially crafted commands to the AI chat interface, an attacker could bypass security controls to view data they are not supposed to see. This could lead to the exposure of confidential corporate or personal information stored within the Microsoft 365 environment.

Technical details

A command injection vulnerability (CWE-138) exists in Microsoft 365 Copilot due to improper neutralization of special elements within user-supplied commands. An unauthenticated attacker can exploit this over the network by submitting malicious input to the Copilot interface. Successful exploitation allows the attacker to bypass intended command boundaries and gain unauthorized access to information. The vulnerability is rated with a CVSS 3.1 score of 7.5, reflecting high confidentiality impact with no requirement for privileges or user interaction. As an exclusively hosted service, Microsoft typically manages the deployment of fixes directly on the platform.

Affected products

  • Microsoft 365 Copilot Chat All versions

Timeline

  • 2026-05-07: disclosed: Initial publication of CVE-2026-26129
  • 2026-06-01: other: CVE description updated to specify command injection details

References

Related threats