Spoofing Vulnerability in Microsoft 365 Copilot Software
CVE-2026-41100

4.4MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
12 May 2026

What is CVE-2026-41100?

The vulnerability arises from improper access control mechanisms within the Microsoft 365 Copilot, potentially allowing authorized attackers to execute local spoofing attacks. This flaw may enable unauthorized manipulation of user actions, compromising the integrity of the application and posing risks to user data security.

Affected Version(s)

Microsoft 365 Copilot for Android 1.0 < 16.0.19822.20190

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.