Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
The vulnerability results from improper neutralization of special characters in commands processed by Microsoft Copilot (CWE-77 — command injection). An attacker, by inducing user interaction (UI:R), can submit crafted input data containing malicious elements that are executed in the context of the vulnerable application. The scope of impact extends beyond the direct component (S:C — scope change), which increases the potential consequences of the attack.
An attacker can perform unauthorized data tampering or manipulation of Microsoft Copilot service behavior, exposing a high level of breach of confidentiality (C:H) and integrity (I:H) of processed information.
Patches available from the vendor should be applied in accordance with references published in the Microsoft Security Response Center (MSRC) at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41090
Microsoft Copilot — specific versions indicated in the vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41090)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NMicrosoft 365 Copilot
APPMicrosoftall versions
Related vulnerabilities
RCE poprzez deserializację niezaufanych danych w Microsoft 365 Copilot
Command injection w Copilot Chat (Microsoft Edge) — zdalne wykonanie kodu
Open Redirect w Microsoft 365 Copilot umożliwia eskalację uprawnień
Brak uwierzytelnienia w Microsoft 365 Copilot — ujawnienie informacji
Open Redirect w Microsoft 365 Copilot umożliwia eskalację uprawnień