Executive brief
Microsoft Copilot, an AI-powered productivity tool, is affected by a critical security vulnerability that allows unauthorized attackers to manipulate its operations over the network. An attacker could exploit this flaw to tamper with AI responses or perform unauthorized actions, potentially leading to the exposure of sensitive information or the corruption of data. While the attack requires some user interaction, the high severity reflects the potential for significant impact on data integrity and confidentiality.
Technical details
A command injection vulnerability (CWE-77) exists in Microsoft Copilot due to improper neutralization of special elements used in commands. An unauthenticated attacker can exploit this over the network, though the attack requires a level of user interaction (UI:R). The vulnerability has a high impact on confidentiality and integrity (C:H/I:H) and involves a scope change (S:C), suggesting the attacker may be able to influence components beyond the immediate Copilot environment. Microsoft has released information regarding this vulnerability under CVE-2026-41090, and as a hosted service, updates are typically managed by the provider.
Affected products
- Microsoft Copilot
Timeline
- 2026-05-22: disclosed: Vulnerability published by Microsoft and NVD.