CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-41090

CVSS 9.3v3.1pub. 2026-05-22upd. 2026-05-27

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

🤖 AI Analysis
How it works

The vulnerability results from improper neutralization of special characters in commands processed by Microsoft Copilot (CWE-77 — command injection). An attacker, by inducing user interaction (UI:R), can submit crafted input data containing malicious elements that are executed in the context of the vulnerable application. The scope of impact extends beyond the direct component (S:C — scope change), which increases the potential consequences of the attack.

Impact

An attacker can perform unauthorized data tampering or manipulation of Microsoft Copilot service behavior, exposing a high level of breach of confidentiality (C:H) and integrity (I:H) of processed information.

Mitigation & patch

Patches available from the vendor should be applied in accordance with references published in the Microsoft Security Response Center (MSRC) at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41090

Who is affected

Microsoft Copilot — specific versions indicated in the vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41090)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Microsoft 365 Copilot

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-50517CRITICAL9.9PL ✓same product

RCE poprzez deserializację niezaufanych danych w Microsoft 365 Copilot

CVE-2026-48561CRITICAL9.6PL ✓same product

Command injection w Copilot Chat (Microsoft Edge) — zdalne wykonanie kodu

CVE-2026-41106CRITICAL9.3PL ✓same product

Open Redirect w Microsoft 365 Copilot umożliwia eskalację uprawnień

CVE-2026-54130CRITICAL9.8PL ✓same product

Brak uwierzytelnienia w Microsoft 365 Copilot — ujawnienie informacji

CVE-2026-33102CRITICAL9.3PL ✓same product

Open Redirect w Microsoft 365 Copilot umożliwia eskalację uprawnień