Junglewise Threat Intelligence

CVE-2026-45497: Microsoft Copilot command injection

CVE-2026-45497 · Severity: high · CVSS 7.7 · Published 2026-06-04

Vendors: Microsoft.

Executive brief

A command injection vulnerability has been identified in Microsoft Copilot, an AI-powered productivity tool. An authorized user could potentially exploit this flaw to execute unauthorized commands or code within the service environment. This could lead to unauthorized access to sensitive data or disruption of the AI service's operations.

Technical details

A command injection vulnerability (CWE-77) exists in Microsoft Copilot due to improper neutralization of special elements used in commands. An attacker with low-level privileges (PR:L) can exploit this over the network, though the attack complexity is rated as high (AC:H). Successful exploitation allows for remote code execution, potentially resulting in a scope change (S:C) that impacts the confidentiality, integrity, and availability of the underlying system. The vulnerability was disclosed by Microsoft, and as a hosted service, updates are typically managed by the provider.

Affected products

  • Microsoft Copilot

Timeline

  • 2026-06-04: disclosed: Initial publication of CVE-2026-45497
  • 2026-06-04: advisory: Microsoft Security Response Center advisory published

References