Junglewise Threat Intelligence

CVE-2026-26164: Microsoft M365 Copilot command injection information disclosure

CVE-2026-26164 · Severity: high · CVSS 7.5 · Published 2026-05-07

Technologies: Microsoft 365 Copilot. Vendors: Microsoft.

Executive brief

Microsoft 365 Copilot, an AI-powered productivity tool, is vulnerable to a command injection flaw. This vulnerability allows an unauthorized person to remotely access and disclose sensitive information over the network. Because this is a hosted service, the impact could involve the exposure of corporate data processed by the AI assistant.

Technical details

A command injection vulnerability exists in Microsoft 365 Copilot due to improper neutralization of special elements used in a command (CWE-74). An unauthenticated attacker can exploit this over the network without user interaction (AV:N/AC:L/PR:N/UI:N). Successful exploitation results in unauthorized information disclosure (Confidentiality: High). As an exclusively hosted service, Microsoft typically manages the remediation on the backend, though the vulnerability was officially disclosed in May 2026.

Affected products

  • Microsoft 365 Copilot All versions (Exclusively Hosted Service)

Timeline

  • 2026-05-07: disclosed: Initial disclosure by Microsoft Corporation
  • 2026-05-07: advisory: NVD published the CVE record
  • 2026-06-01: other: Description updated to clarify command injection nature

References

Related threats