CVE-2026-42824: M365 Copilot Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Other sources
M365 Copilot Information Disclosure Vulnerability
— Microsoft
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Require and enforce authentication for the affected critical function(s) to prevent unauthenticated disclosure of information over the network.
M365 Copilot authentication_for_critical_function = enabled - Configuration
Implement proper neutralization/validation of special elements used in commands (sanitize or validate command inputs) to prevent command injection.
M365 Copilot input_neutralization_for_commands = properly neutralize special command elements - Compensating control
Until fixes are applied, restrict network access to the M365 Copilot component and the affected function (for example via firewall rules, IP allowlists, or network segmentation) to limit exposure and reduce risk of unauthorized information disclosure.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42824?
The severity of CVE-2026-42824 is medium with a score of 6.5.
What systems are affected by CVE-2026-42824?
CVE-2026-42824 affects Microsoft 365 Copilot.
How do I fix CVE-2026-42824?
To fix CVE-2026-42824, apply the necessary security updates provided by Microsoft.
What type of vulnerability is CVE-2026-42824?
CVE-2026-42824 is classified as a command injection vulnerability.
What could be the impact of exploiting CVE-2026-42824?
Exploiting CVE-2026-42824 could allow an unauthorized attacker to disclose sensitive information over a network.