CVE-2026-26129CWE-138

M365 Copilot Information Disclosure Vulnerability

High · published May 7, 2026

CVSS v3.1
7.5
EPSS
1%
Percentile
64.3
In the wild
Unconfirmed
What it is

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
CVSS v4.0
Not supplied
EPSS
0.01135 · 64.3th percentile
Weakness
CWE-138 · Improper Neutralization of Special Elements
Published
2026-05-07T20:58Z
EPSS history
Timeline
  • 07 MAY 20:58Z
    M365 Copilot Information Disclosure Vulnerability
    cvelistv5