Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.
The vulnerability (CWE-1287) indicates that the application does not properly validate the type of supplied input data, accepting data that does not conform to the expected format or type. An attacker can submit specially crafted input data over the network, prompting the user to interact with it (requires victim action, UI:R). The network attack vector (AV:N) without authentication requirement (PR:N) and scope change (S:C) indicates that impacts may extend beyond the direct application context.
An attacker can gain unauthorized access to sensitive information processed by Microsoft 365 Copilot, potentially including user organizational data. Data integrity is not directly threatened; however, information disclosure may lead to serious privacy and data security breaches.
Apply patches available from the vendor in accordance with references published at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24307. It is recommended to regularly monitor the Microsoft Security Update Guide to verify patch availability.
Microsoft 365 Copilot — specific versions indicated in vendor references (Microsoft Security Response Center).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NMicrosoft 365 Copilot
APPMicrosoftall versions
Related vulnerabilities
RCE poprzez deserializację niezaufanych danych w Microsoft 365 Copilot
Command injection w Copilot Chat (Microsoft Edge) — zdalne wykonanie kodu
Open Redirect w Microsoft 365 Copilot umożliwia eskalację uprawnień
Brak uwierzytelnienia w Microsoft 365 Copilot — ujawnienie informacji
Command injection w Microsoft Copilot umożliwiający manipulację danymi