Command Injection Vulnerability in Outlook Copilot by Microsoft
CVE-2026-55145

6.3MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
14 July 2026

What is CVE-2026-55145?

The command injection vulnerability in Outlook Copilot allows an authorized attacker to manipulate commands within the application. By exploiting this flaw, attackers can tamper with data transmitted over the network, potentially leading to unauthorized access or modification of sensitive information. Users are advised to update to the latest version of Outlook Copilot to mitigate this risk.

Affected Version(s)

Microsoft Copilot -

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.