CVE-2026-85887: M365 Copilot Information Disclosure Vulnerability
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
Other sources
M365 Copilot Information Disclosure Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authorized and have low-level privileges. Exploitation is network-based, requires low attack complexity, and does not require user interaction.
What is the expected security impact if exploitation succeeds?
The vulnerability can result in high-impact disclosure of confidential information. The supplied vector indicates no direct integrity or availability impact, while the scope may extend beyond the initially affected security authority.
Is there evidence that a default configuration is affected or that compensating controls are available?
The provided information does not state whether default configurations are affected or identify any compensating controls for environments where patching is delayed.