Command Injection Vulnerability in Outlook Copilot by Microsoft
CVE-2026-55145
6.3MEDIUM
What is CVE-2026-55145?
The command injection vulnerability in Outlook Copilot allows an authorized attacker to manipulate commands within the application. By exploiting this flaw, attackers can tamper with data transmitted over the network, potentially leading to unauthorized access or modification of sensitive information. Users are advised to update to the latest version of Outlook Copilot to mitigate this risk.
Affected Version(s)
Microsoft Copilot -