Command Injection Vulnerability in Microsoft Copilot
CVE-2026-42895
6.5MEDIUM
What is CVE-2026-42895?
An improper neutralization of special elements used in command inputs in Microsoft Copilot allows unauthorized individuals to execute command injection attacks. This vulnerability could lead to network tampering, enabling attackers to manipulate the behavior of the software and potentially compromise sensitive data. It is essential for users to apply available patches to mitigate this risk and secure their systems.
Affected Version(s)
Microsoft 365 Copilot -