Command injection flaws in Microsoft Copilot and M365 Copilot allow information disclosure
Two CVEs (CVE-2026-24299 and CVE-2026-26136) describe improper neutralization of special elements used in a command in M365 Copilot and Microsoft Copilot, allowing an unauthorized attacker to disclose information over a network. Microsoft published advisories for both issues via MSRC.
Disclosed 19 March 2026 · Record updated 13 September 2026
Impact
An unauthorized attacker could disclose information over a network by exploiting command injection in Copilot.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-24299
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-26136
