Junglewise Threat Intelligence

CVE-2026-41100: Microsoft M365 Copilot improper access control spoofing

CVE-2026-41100 · Severity: medium · CVSS 4.4 · Published 2026-05-12

Technologies: Microsoft 365 Copilot. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft 365 Copilot, the AI-powered productivity tool integrated into Microsoft Office applications. An attacker with existing local access to a system could exploit this flaw to impersonate other users or services. This could lead to unauthorized actions being performed under a false identity, potentially compromising the integrity of internal communications or data.

Technical details

A vulnerability classified as improper access control (CWE-284) exists within Microsoft 365 Copilot. The flaw allows an attacker who is already authenticated to the local system to perform spoofing attacks. With a CVSS vector of AV:L/AC:L/PR:L/UI:N, the attack requires local access and low privileges but no user interaction. Successful exploitation allows the attacker to compromise the integrity and confidentiality of the application's operations by masquerading as a legitimate entity. Microsoft has released information regarding this vulnerability via the MSRC Update Guide.

Affected products

  • Microsoft Copilot M365 Copilot

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Microsoft published the security advisory.

References

Related threats