AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Microsoft
Subscribe
|
365 Copilot Android
Subscribe
365 Copilot Ios
Subscribe
Edge
Subscribe
Excel
Subscribe
Loop
Subscribe
Onenote For Android
Subscribe
Onenote For Ios
Subscribe
Outlook
Subscribe
Outlook 2016
Subscribe
Power Bi Android
Subscribe
Power Bi Ios
Subscribe
Powerpoint
Subscribe
Teams
Subscribe
Word
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 13 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Title | M365 Copilot Information Disclosure Vulnerability | |
| First Time appeared |
Microsoft
Microsoft 365 Copilot Android Microsoft 365 Copilot Ios Microsoft edge Microsoft excel Microsoft loop Microsoft onenote For Android Microsoft onenote For Ios Microsoft outlook Microsoft outlook 2016 Microsoft power Bi Android Microsoft power Bi Ios Microsoft powerpoint Microsoft teams Microsoft word |
|
| CPEs | cpe:2.3:a:microsoft:365_copilot_Android:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:365_copilot_iOS:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:edge:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:excel:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:excel:*:*:iOS:*:*:*:*:* cpe:2.3:a:microsoft:loop:*:*:iOS:*:*:*:*:* cpe:2.3:a:microsoft:onenote_for_android:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:onenote_for_ios:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:outlook:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:outlook:*:*:*:*:*:macos:*:* cpe:2.3:a:microsoft:outlook_2016:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:power_bi_android:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:power_bi_iOS:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:powerpoint:*:*:iOS:*:*:*:*:* cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:teams:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:word:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:word:*:*:iOS:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft 365 Copilot Android Microsoft 365 Copilot Ios Microsoft edge Microsoft excel Microsoft loop Microsoft onenote For Android Microsoft onenote For Ios Microsoft outlook Microsoft outlook 2016 Microsoft power Bi Android Microsoft power Bi Ios Microsoft powerpoint Microsoft teams Microsoft word |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-03-13T22:25:36.382Z
Reserved: 2026-02-11T16:24:51.133Z
Link: CVE-2026-26133
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.