Junglewise Threat Intelligence

CVE-2026-41106: Microsoft M365 Copilot open redirect privilege escalation

CVE-2026-41106 · Severity: critical · CVSS 9.3 · Published 2026-07-02

Technologies: Microsoft M365 Copilot, Microsoft 365 Copilot. Vendors: Microsoft.

Executive brief

Microsoft 365 Copilot, an AI-powered productivity tool, contains a security flaw that allows attackers to redirect users to malicious websites. By tricking a user into clicking a specially crafted link, an attacker can gain unauthorized access to sensitive information or take over the user's session. This could lead to the theft of corporate data or unauthorized actions performed on behalf of the employee.

Technical details

An open redirect vulnerability (CWE-601) exists in Microsoft 365 Copilot due to improper validation of user-supplied URL input. An unauthenticated remote attacker can exploit this by sending a link with a specially crafted URL to a target user. If the user clicks the link, they are redirected to an external, untrusted domain controlled by the attacker. In the context of M365 Copilot, this flaw is rated as critical because it can be leveraged to facilitate privilege escalation and the theft of sensitive session tokens or credentials. The vulnerability is tracked as CVE-2026-41106 and has a CVSS 3.1 score of 9.3.

Affected products

  • Microsoft Microsoft 365 Copilot All versions

Timeline

  • 2026-07-02: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats