Junglewise Threat Intelligence

CVE-2026-55946: Microsoft Copilot command injection

CVE-2026-55946 · Severity: medium · CVSS 6.1 · Published 2026-09-17

Vendors: Microsoft.

Executive brief

Microsoft Copilot contains a command injection vulnerability that allows an attacker to send specially crafted commands and access sensitive information transmitted over the network. This flaw could enable unauthorized disclosure of data that should remain confidential, potentially exposing user information or internal system details.

Technical details

A command injection vulnerability exists in Microsoft Copilot due to improper neutralization of special elements in user-supplied input. The vulnerability allows an attacker to inject malicious commands that are executed by the application. An unauthorized attacker can leverage this vulnerability to disclose sensitive information over a network. The attack does not require authentication or user interaction beyond sending a crafted request to the vulnerable component. Patches are expected to be available through Microsoft's standard security update channels.

Affected products

  • Microsoft Copilot

Timeline

  • 2026-09-17: disclosed

References