Information Disclosure Vulnerability in M365 Copilot by Microsoft
CVE-2026-26164
7.5HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 7 May 2026
What is CVE-2026-26164?
An information disclosure vulnerability exists in M365 Copilot due to improper neutralization of special elements in output. This flaw may allow unauthorized attackers to expose sensitive information over a network, potentially compromising data integrity and privacy for users of the affected product.
Affected Version(s)
Microsoft 365 Copilot's Business Chat -