Command Injection Vulnerability in Microsoft Copilot
CVE-2026-42895

6.5MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
19 June 2026

What is CVE-2026-42895?

An improper neutralization of special elements used in command inputs in Microsoft Copilot allows unauthorized individuals to execute command injection attacks. This vulnerability could lead to network tampering, enabling attackers to manipulate the behavior of the software and potentially compromise sensitive data. It is essential for users to apply available patches to mitigate this risk and secure their systems.

Affected Version(s)

Microsoft 365 Copilot -

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.