CVE-2026-26133: M365 Copilot Information Disclosure Vulnerability

Overview

Severity
High (CVSS 7.1)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Mar
Released
2026-03-12
Last Updated
2026-03-12

Description

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

FAQ

According to the CVSS metric, the attack vector is network (AV:N) and user interaction is required (UI:R). Why does the CVE title indicate that this is information disclosure? An attacker who successfully exploited this vulnerability could use malicious email to cause Copilot to present authoritative‑looking phishing messages that prompt the user to click links leading to data exfiltration or navigation to a malicious site. According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H), and some loss of integrity (I:L), but no loss of availability (A:N). What does that mean for this vulnerability? An attacker who successfully exploited this vulnerability could potentially view sensitive information (confidentiality) or make limited changes to disclosed information (integrity); however, it is unlikely that both would be impacted simultaneously, and the attacker would not be able to affect availability.

Affected Products (20)

Microsoft Office

  • Microsoft OneNote for iOS
  • Microsoft Outlook for Mac
  • Microsoft Teams for iOS
  • Microsoft Teams for Android
  • Microsoft Excel for Android
  • Microsoft PowerPoint for iOS
  • Microsoft Word for iOS
  • Microsoft Loop for iOS
  • Microsoft Outlook for iOS
  • Microsoft OneNote for Android
  • Microsoft PowerPoint for Android
  • Microsoft Excel for iOS

Apps

  • Microsoft Outlook for Android
  • Microsoft 365 Copilot for iOS
  • Microsoft Word for Android
  • Microsoft 365 Copilot for Android

Browser

  • Microsoft Edge for Android
  • Microsoft Edge for iOS

SQL Server

  • Microsoft PowerBI for Android
  • Microsoft PowerBI for iOS

Security Updates (18)

Acknowledgments

Andi Ahmeti <a href="(https://www.linkedin.com/in/andi-ahmeti/)"></a> with Permiso Security <a href="(https://permiso.io/)/"></a>

Revision History

  • 2026-03-12: Information published.
  • 2026-03-12: Updated an acknowledgement. This is an informational change only.