CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-24307

CVSS 9.3v3.1pub. 2026-01-22upd. 2026-02-12

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

🤖 AI Analysis
How it works

The vulnerability (CWE-1287) indicates that the application does not properly validate the type of supplied input data, accepting data that does not conform to the expected format or type. An attacker can submit specially crafted input data over the network, prompting the user to interact with it (requires victim action, UI:R). The network attack vector (AV:N) without authentication requirement (PR:N) and scope change (S:C) indicates that impacts may extend beyond the direct application context.

Impact

An attacker can gain unauthorized access to sensitive information processed by Microsoft 365 Copilot, potentially including user organizational data. Data integrity is not directly threatened; however, information disclosure may lead to serious privacy and data security breaches.

Mitigation & patch

Apply patches available from the vendor in accordance with references published at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24307. It is recommended to regularly monitor the Microsoft Security Update Guide to verify patch availability.

Who is affected

Microsoft 365 Copilot — specific versions indicated in vendor references (Microsoft Security Response Center).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Microsoft 365 Copilot

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-50517CRITICAL9.9PL ✓same product

RCE poprzez deserializację niezaufanych danych w Microsoft 365 Copilot

CVE-2026-48561CRITICAL9.6PL ✓same product

Command injection w Copilot Chat (Microsoft Edge) — zdalne wykonanie kodu

CVE-2026-41106CRITICAL9.3PL ✓same product

Open Redirect w Microsoft 365 Copilot umożliwia eskalację uprawnień

CVE-2026-54130CRITICAL9.8PL ✓same product

Brak uwierzytelnienia w Microsoft 365 Copilot — ujawnienie informacji

CVE-2026-41090CRITICAL9.3PL ✓same product

Command injection w Microsoft Copilot umożliwiający manipulację danymi