Command Injection Vulnerability in M365 Copilot by Microsoft
CVE-2026-42893
7.4HIGH
What is CVE-2026-42893?
An improper neutralization of special elements used in command execution within M365 Copilot enables attackers to execute unauthorized commands over a network, leading to potential tampering and data exposure.
Affected Version(s)
Microsoft Outlook for iOS 1.0.0 < 5.2617.1