← Back

CVE-2026-26133

nvd nist
Published: Mar 16, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Exploitability: 2.8 / Impact: 4.2
Source: secure@microsoft.com (Secondary)

Description

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Affected (20)

10 products
365 Copilot
Edge
Excel
Loop
Onenote
Outlook
Power Bi
Powerpoint
Teams
Word
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Before 16.0.19815.10000
Before 2.107.2
Microsoft
Before 145.3800.99
Before 145.3800.99
Microsoft
Before 16.0.19822.20038
Before 2.106.2
Before 2.106
Microsoft
Before 16.0.19725.20142
All versions
Microsoft
Before 5.2605.0
Before 5.2605.0
All versions
Microsoft
Before 2.2.260210.21290750
All versions
Microsoft
Before 16.0.19822.20038
Before 2.106.2
Microsoft
Before 1.0.0.2026043102
Before 8.3.1
Microsoft
Before 16.0.19822.20038
Before 2.106.2

References (1)

Timeline

No history available yet.