CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-41106

CVSS 9.3v3.1pub. 2026-07-02upd. 2026-07-07

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-601 (URL Redirection to Untrusted Site) consists in the fact that the Microsoft 365 Copilot application does not properly verify the target URL before executing the redirect. An attacker can craft a malicious link that, when clicked by a victim (requiring user interaction — UI:R), redirects them to a page controlled by the attacker. The network vector (AV:N) and lack of required privileges (PR:N) mean that the attack can be conducted remotely by anyone. The scope of the attack extends beyond the source component (S:C), indicating the possibility of impacting other resources in the environment.

Impact

An attacker can lead to privilege escalation and breach the confidentiality and integrity of the victim's data, potentially hijacking the session or stealing user authentication credentials through phishing assisted by redirection.

Mitigation & patch

Apply patches available from the vendor according to references published in the Microsoft Security Response Center (MSRC): https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41106

Who is affected

Microsoft 365 Copilot — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Microsoft 365 Copilot

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-50517CRITICAL9.9PL ✓same product

RCE poprzez deserializację niezaufanych danych w Microsoft 365 Copilot

CVE-2026-48561CRITICAL9.6PL ✓same product

Command injection w Copilot Chat (Microsoft Edge) — zdalne wykonanie kodu

CVE-2026-54130CRITICAL9.8PL ✓same product

Brak uwierzytelnienia w Microsoft 365 Copilot — ujawnienie informacji

CVE-2026-41090CRITICAL9.3PL ✓same product

Command injection w Microsoft Copilot umożliwiający manipulację danymi

CVE-2026-33102CRITICAL9.3PL ✓same product

Open Redirect w Microsoft 365 Copilot umożliwia eskalację uprawnień