Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
The vulnerability classified as CWE-601 (URL Redirection to Untrusted Site) consists in the fact that the Microsoft 365 Copilot application does not properly verify the target URL before executing the redirect. An attacker can craft a malicious link that, when clicked by a victim (requiring user interaction — UI:R), redirects them to a page controlled by the attacker. The network vector (AV:N) and lack of required privileges (PR:N) mean that the attack can be conducted remotely by anyone. The scope of the attack extends beyond the source component (S:C), indicating the possibility of impacting other resources in the environment.
An attacker can lead to privilege escalation and breach the confidentiality and integrity of the victim's data, potentially hijacking the session or stealing user authentication credentials through phishing assisted by redirection.
Apply patches available from the vendor according to references published in the Microsoft Security Response Center (MSRC): https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41106
Microsoft 365 Copilot — versions indicated in vendor references
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NMicrosoft 365 Copilot
APPMicrosoftall versions
Related vulnerabilities
RCE poprzez deserializację niezaufanych danych w Microsoft 365 Copilot
Command injection w Copilot Chat (Microsoft Edge) — zdalne wykonanie kodu
Brak uwierzytelnienia w Microsoft 365 Copilot — ujawnienie informacji
Command injection w Microsoft Copilot umożliwiający manipulację danymi
Open Redirect w Microsoft 365 Copilot umożliwia eskalację uprawnień