AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 13 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Title | M365 Copilot Information Disclosure Vulnerability | |
| First Time appeared |
Microsoft
Microsoft 365 Copilot Android Microsoft 365 Copilot Ios Microsoft edge Microsoft excel Microsoft loop Microsoft onenote For Android Microsoft onenote For Ios Microsoft outlook Microsoft outlook 2016 Microsoft power Bi Android Microsoft power Bi Ios Microsoft powerpoint Microsoft teams Microsoft word |
|
| CPEs | cpe:2.3:a:microsoft:365_copilot_Android:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:365_copilot_iOS:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:edge:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:excel:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:excel:*:*:iOS:*:*:*:*:* cpe:2.3:a:microsoft:loop:*:*:iOS:*:*:*:*:* cpe:2.3:a:microsoft:onenote_for_android:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:onenote_for_ios:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:outlook:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:outlook:*:*:*:*:*:macos:*:* cpe:2.3:a:microsoft:outlook_2016:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:power_bi_android:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:power_bi_iOS:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:powerpoint:*:*:iOS:*:*:*:*:* cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:teams:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:word:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:word:*:*:iOS:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft 365 Copilot Android Microsoft 365 Copilot Ios Microsoft edge Microsoft excel Microsoft loop Microsoft onenote For Android Microsoft onenote For Ios Microsoft outlook Microsoft outlook 2016 Microsoft power Bi Android Microsoft power Bi Ios Microsoft powerpoint Microsoft teams Microsoft word |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-03-13T22:25:36.382Z
Reserved: 2026-02-11T16:24:51.133Z
Link: CVE-2026-26133
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.