Junglewise Threat Intelligence

CVE-2026-42827: Microsoft M365 Copilot command injection

CVE-2026-42827 · Severity: medium · CVSS 6.5 · Published 2026-05-22

Executive brief

Microsoft M365 Copilot, an AI-powered productivity tool, is vulnerable to a command injection flaw. This security issue could allow an unauthorized attacker to trick the system into disclosing sensitive information over the network. Successful exploitation could lead to the unauthorized exposure of corporate or personal data handled by the AI assistant.

Technical details

A command injection vulnerability (CWE-77) exists in Microsoft M365 Copilot due to improper neutralization of special elements used in commands. An unauthenticated attacker can exploit this over the network, though the CVSS vector indicates that user interaction is required (UI:R). Successful exploitation allows for unauthorized information disclosure (Confidentiality: High), potentially leaking sensitive data processed by the Copilot service. The vulnerability is specific to the M365 Copilot hosted service environment.

Affected products

  • Microsoft M365 Copilot

Timeline

  • 2026-05-22: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats