CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-33102

CVSS 9.3v3.1pub. 2026-04-23upd. 2026-04-29

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

🤖 AI Analysis
How it works

The vulnerability consists in the possibility of redirecting a user to an untrusted external website through a crafted URL (CWE-601 — URL Redirection to Untrusted Site). An attacker can trick the victim into clicking a malicious link that appears to point to a trusted Microsoft 365 Copilot domain, but actually redirects to a page controlled by the attacker. User interaction is required (UI:R), however the attacker does not need any prior privileges or authentication. This mechanism can be exploited to steal credentials or carry out further stages of an attack with elevated privileges.

Impact

An attacker can cause privilege escalation in the network context and expose the victim to high risk of confidentiality and integrity breach, potentially gaining access to resources beyond the original scope of the application.

Mitigation & patch

Apply patches available from the vendor according to references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33102. Additionally, it is recommended to educate users on verifying URLs before clicking links and implementing proxy filtering with outbound traffic inspection.

Who is affected

Microsoft 365 Copilot — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Microsoft 365 Copilot

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-50517CRITICAL9.9PL ✓same product

RCE poprzez deserializację niezaufanych danych w Microsoft 365 Copilot

CVE-2026-48561CRITICAL9.6PL ✓same product

Command injection w Copilot Chat (Microsoft Edge) — zdalne wykonanie kodu

CVE-2026-41106CRITICAL9.3PL ✓same product

Open Redirect w Microsoft 365 Copilot umożliwia eskalację uprawnień

CVE-2026-54130CRITICAL9.8PL ✓same product

Brak uwierzytelnienia w Microsoft 365 Copilot — ujawnienie informacji

CVE-2026-41090CRITICAL9.3PL ✓same product

Command injection w Microsoft Copilot umożliwiający manipulację danymi