Information Disclosure Vulnerability in M365 Copilot by Microsoft
CVE-2026-26164
7.5HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 7 May 2026
Badges
๐พ Exploit Exists๐ฐ News Worthy
What is CVE-2026-26164?
An information disclosure vulnerability exists in M365 Copilot due to improper neutralization of special elements in output. This flaw may allow unauthorized attackers to expose sensitive information over a network, potentially compromising data integrity and privacy for users of the affected product.
Affected Version(s)
Microsoft 365 Copilot's Business Chat -
News Articles
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by Cybersecuritynews
Vulnerability published
Vulnerability Reserved