Command Injection Vulnerability in M365 Copilot by Microsoft
CVE-2026-24299
5.3MEDIUM
What is CVE-2026-24299?
The M365 Copilot product from Microsoft contains a vulnerability that stems from improper neutralization of special elements in commands, enabling unauthorized attackers to potentially disclose sensitive information over a network. This flaw poses a risk to the integrity of data handled by the Copilot, necessitating immediate attention and remediation to protect users and systems.
Affected Version(s)
Microsoft 365 Copilot -