Information Disclosure Vulnerability in M365 Copilot by Microsoft
CVE-2026-24307
9.3CRITICAL
What is CVE-2026-24307?
An improper validation of specific input types in M365 Copilot allows unauthorized attackers to disclose sensitive information over the network. This vulnerability highlights the importance of input validation in software development and underlines potential risks associated with inadequate security measures. Organizations utilizing M365 Copilot should implement precautionary measures to mitigate exposure and safeguard against possible information leaks.
Affected Version(s)
Microsoft 365 Copilot -