AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Project Subscriptions

Vendors Products
Microsoft Subscribe
365 Copilot Android Subscribe
365 Copilot For Android Subscribe
365 Copilot For Ios Subscribe
365 Copilot Ios Subscribe
Edge For Android Subscribe
Edge For Ios Subscribe
Excel For Android Subscribe
Excel For Ios Subscribe
Loop For Ios Subscribe
Onenote Subscribe
Onenote For Android Subscribe
Onenote For Ios Subscribe
Outlook Subscribe
Outlook 2016 Subscribe
Outlook For Android Subscribe
Outlook For Ios Subscribe
Outlook For Mac Subscribe
Power Bi Android Subscribe
Power Bi Ios Subscribe
Powerbi For Android Subscribe
Powerbi For Ios Subscribe
Powerpoint Subscribe
Powerpoint For Android Subscribe
Powerpoint For Ios Subscribe
Teams For Android Subscribe
Teams For Ios Subscribe
Word For Android Subscribe
Word For Ios Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 16 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft 365 Copilot For Android
Microsoft 365 Copilot For Ios
Microsoft edge For Android
Microsoft edge For Ios
Microsoft excel For Android
Microsoft excel For Ios
Microsoft loop For Ios
Microsoft onenote
Microsoft outlook For Android
Microsoft outlook For Ios
Microsoft outlook For Mac
Microsoft powerbi For Android
Microsoft powerbi For Ios
Microsoft powerpoint For Android
Microsoft powerpoint For Ios
Microsoft teams For Android
Microsoft teams For Ios
Microsoft word For Android
Microsoft word For Ios
Vendors & Products Microsoft 365 Copilot For Android
Microsoft 365 Copilot For Ios
Microsoft edge For Android
Microsoft edge For Ios
Microsoft excel For Android
Microsoft excel For Ios
Microsoft loop For Ios
Microsoft onenote
Microsoft outlook For Android
Microsoft outlook For Ios
Microsoft outlook For Mac
Microsoft powerbi For Android
Microsoft powerbi For Ios
Microsoft powerpoint For Android
Microsoft powerpoint For Ios
Microsoft teams For Android
Microsoft teams For Ios
Microsoft word For Android
Microsoft word For Ios

Fri, 13 Mar 2026 21:30:00 +0000

Type Values Removed Values Added
Description AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Title M365 Copilot Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Copilot Android
Microsoft 365 Copilot Ios
Microsoft edge
Microsoft excel
Microsoft loop
Microsoft onenote For Android
Microsoft onenote For Ios
Microsoft outlook
Microsoft outlook 2016
Microsoft power Bi Android
Microsoft power Bi Ios
Microsoft powerpoint
Microsoft teams
Microsoft word
CPEs cpe:2.3:a:microsoft:365_copilot_Android:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:365_copilot_iOS:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:excel:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:excel:*:*:iOS:*:*:*:*:*
cpe:2.3:a:microsoft:loop:*:*:iOS:*:*:*:*:*
cpe:2.3:a:microsoft:onenote_for_android:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:onenote_for_ios:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:outlook:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:outlook:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:outlook_2016:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:power_bi_android:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:power_bi_iOS:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:powerpoint:*:*:iOS:*:*:*:*:*
cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:teams:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:word:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:word:*:*:iOS:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Copilot Android
Microsoft 365 Copilot Ios
Microsoft edge
Microsoft excel
Microsoft loop
Microsoft onenote For Android
Microsoft onenote For Ios
Microsoft outlook
Microsoft outlook 2016
Microsoft power Bi Android
Microsoft power Bi Ios
Microsoft powerpoint
Microsoft teams
Microsoft word
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-03-19T21:21:21.556Z

Reserved: 2026-02-11T16:24:51.133Z

Link: CVE-2026-26133

cve-icon Vulnrichment

Updated: 2026-03-16T14:24:27.333Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-16T14:18:26.337

Modified: 2026-03-16T14:53:07.390

Link: CVE-2026-26133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-16T09:22:50Z

Weaknesses

No weakness.