Executive brief
A critical security flaw has been identified in Microsoft 365 Copilot, an AI-powered productivity tool integrated into Microsoft applications. This vulnerability allows an unauthorized person to access sensitive information over the network without needing a password or any special permissions. This could lead to the exposure of private corporate data and a complete compromise of the service's integrity and availability.
Technical details
A missing authentication vulnerability (CWE-306) exists in Microsoft 365 Copilot. The flaw resides in a critical function that fails to verify the identity of the requester, allowing an unauthenticated attacker to invoke the function over a network. Successful exploitation grants the attacker the ability to disclose sensitive information and potentially achieve full control over the affected component's confidentiality, integrity, and availability. As this is an exclusively hosted service, Microsoft typically manages the deployment of fixes directly on the backend.
Affected products
- Microsoft Microsoft 365 Copilot All versions
Timeline
- 2026-06-18: disclosed
- 2026-06-18: advisory