CVE-2026-42893: Microsoft Outlook for iOS Tampering Vulnerability
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.
Other sources
Microsoft Outlook for iOS Tampering Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.2617.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42893?
CVE-2026-42893 is classified as a critical vulnerability due to its potential for unauthorized command injection.
How do I fix CVE-2026-42893?
To fix CVE-2026-42893, update Microsoft Outlook for iOS to the latest version available in the app store.
Which versions of Outlook for iOS are affected by CVE-2026-42893?
CVE-2026-42893 affects Microsoft Outlook for iOS versions prior to 5.2617.1.
What does CVE-2026-42893 allow an attacker to do?
CVE-2026-42893 allows an attacker to perform tampering over a network through command injection.
Is there a patch available for CVE-2026-42893?
Yes, a patch is available and can be applied by updating Microsoft Outlook for iOS.