Junglewise Threat Intelligence

CVE-2026-85887: Microsoft M365 Copilot incorrect permission assignment in critical resource

CVE-2026-85887 · Severity: high · CVSS 7.7 · Published 2026-09-18

Executive brief

M365 Copilot is Microsoft's AI-powered productivity assistant integrated into Microsoft 365 applications. An incorrect permission assignment on a critical resource allows an authorized user to access and disclose information they should not have access to, potentially exposing sensitive business data across the network.

Technical details

This vulnerability is rooted in incorrect permission assignment for a critical resource within M365 Copilot. An authenticated attacker (one who already has authorized access to M365) can exploit improper access controls to access and exfiltrate information they are not entitled to. The attack vector is network-based and requires the attacker to be an authorized user of the system. The vulnerability enables information disclosure, allowing sensitive data to be exposed. Patches from Microsoft are expected to be available through the standard security update process.

Affected products

  • Microsoft M365 Copilot

Timeline

  • 2026-09-18: disclosed

References

Related threats