CVE-2026-80098: Copilot Studio Elevation of Privilege Vulnerability
Published Sep 3, 2026
·Updated
Copilot Studio Elevation of Privilege Vulnerability
Other sources
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
1 affected component
Microsoft Copilot Studio
Event History
Sep 3, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·10:59 PM
Data Sourced
via MITRE·10:59 PM
DescriptionSeverity
Frequently Asked Questions
1
What does an attacker need to attempt exploitation?
The supplied CVSS vector indicates network access is required. It also indicates low attack complexity, no prior privileges, and no user interaction are required.
2
What is the likely security impact if exploitation succeeds?
An unauthorized attacker could elevate privileges. The supplied impact metrics indicate high integrity impact, low confidentiality impact, and no availability impact.