CVE-2026-26136: Microsoft Copilot Information Disclosure Vulnerability
Published Mar 19, 2026
·Updated
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
Other sources
Microsoft Copilot Information Disclosure Vulnerability
— Microsoft
Affected Software
2 affected components
Microsoft Copilot
Microsoft Copilot
Event History
Mar 19, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·09:06 PM
Data Sourced
via MITRE·09:06 PM
DescriptionSeverity
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeaknessAffected Software
Jan 23, 58219
Event
via NVD·08:24 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-26136?
The CVE-2026-26136 vulnerability has a severity rating that indicates a significant risk of information disclosure.
2
How do I fix CVE-2026-26136?
To fix CVE-2026-26136, update Microsoft Copilot to the latest version provided by Microsoft.
3
What type of vulnerability is CVE-2026-26136?
CVE-2026-26136 is an information disclosure vulnerability related to command injection.
4
Who is affected by CVE-2026-26136?
Users of Microsoft Copilot are potentially affected by CVE-2026-26136.
5
What could be the impact of CVE-2026-26136?
The impact of CVE-2026-26136 could allow unauthorized attackers to disclose sensitive information over a network.