Junglewise Threat Intelligence

CVE-2026-47645: Microsoft 365 Copilot open redirect in Business Chat

CVE-2026-47645 · Severity: high · CVSS 8.8 · Published 2026-06-19

Vendors: Microsoft.

Executive brief

Microsoft 365 Copilot's Business Chat, an AI-powered productivity tool, contains a security flaw that could allow an attacker to redirect users to malicious websites. By tricking a user into clicking a specially crafted link, an attacker could potentially gain unauthorized access to sensitive information or elevate their permissions within the environment. This could lead to data theft or unauthorized actions being performed on behalf of the user.

Technical details

An open redirect vulnerability (CWE-601) exists in the Business Chat component of Microsoft 365 Copilot. The flaw stems from insufficient validation of URL parameters, allowing an attacker to construct a link that redirects a legitimate user to an external, malicious domain. While the attack requires user interaction (clicking a link), it is reachable over the network without prior authentication. Successful exploitation can lead to privilege escalation, potentially allowing the attacker to capture sensitive session tokens or perform actions in the context of the victim user. Microsoft has addressed this in their hosted service environment.

Affected products

  • Microsoft 365 Copilot Business Chat All versions

Timeline

  • 2026-06-19: disclosed: Initial publication of CVE-2026-47645
  • 2026-06-19: advisory: Microsoft Security Response Center advisory published

References