Command injection flaws in Microsoft Copilot and M365 Copilot (CVE-2026-41090, CVE-2026-42827)
Two command injection vulnerabilities were published for Microsoft's Copilot assistants: CVE-2026-41090 lets an unauthorized attacker perform tampering over a network in Microsoft Copilot, and CVE-2026-42827 lets an unauthorized attacker disclose information over a network in M365 Copilot. Both stem from improper neutralization of special elements used in a command.
Disclosed 22 May 2026 · Record updated 13 September 2026
Impact
Unauthenticated network attackers could tamper with data (Microsoft Copilot) or disclose information (M365 Copilot).
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41090
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42827
