Command Injection and SSRF Vulnerabilities in Microsoft Copilot
Two vulnerabilities were identified in Microsoft Copilot: a command injection flaw (CVE-2026-24301) allowing unauthorized attackers to disclose information, and an SSRF vulnerability (CVE-2026-69855) in Azure allowing authorized attackers to access sensitive data over a network.
Disclosed 18 August 2026 · Record updated 13 September 2026
Impact
Information disclosure via command injection and server-side request forgery attacks against Microsoft Copilot and its Azure deployment.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-24301
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-69855
