CVE-2026-78501: Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability
Published Sep 17, 2026
·Updated
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
Other sources
Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability
— Microsoft
Affected Software
2 affected components
Microsoft Microsoft 365 Copilot
Microsoft 365 Copilot's Business Chat
Event History
Sep 17, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
DescriptionSeverity
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates the attack can be conducted over a network with low attack complexity and requires no privileges. User interaction is required.
2
What is the expected security impact?
The vulnerability is rated high severity with a 7.4 CVSS score. It has high confidentiality impact, while integrity and availability impact are rated as none.