Executive brief
Microsoft 365 Copilot's Business Chat feature is vulnerable to command injection, which allows an attacker to inject malicious commands that execute in the context of the application. This could enable unauthorized disclosure of sensitive business information or data accessible to the affected user's account.
Technical details
The vulnerability is a command injection flaw in Microsoft 365 Copilot's Business Chat component that fails to properly neutralize special elements used in commands. An unauthenticated attacker can exploit this over the network to execute arbitrary commands and access confidential information. The vulnerability has a CVSS score of 7.4 and does not require user interaction or prior authentication. Microsoft has released security updates to address this issue.
Affected products
- Microsoft 365 Copilot <UNKNOWN>
Timeline
- 2026-09-17: disclosed