Open Redirect Vulnerability in Microsoft 365 Copilot's Business Chat
CVE-2026-47645

8.8HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
19 June 2026

What is CVE-2026-47645?

An open redirect vulnerability in the Microsoft 365 Copilot's Business Chat can allow unauthorized attackers to redirect users to untrusted sites. This exposure may enable attackers to exploit the redirection feature to elevate privileges within a network, posing significant risks to sensitive information and overall system security. It's essential for users of Microsoft 365 to be aware of this vulnerability and apply recommended security patches to protect their environments.

Affected Version(s)

Microsoft 365 Copilot -

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.