Skip to content
MicrosoftCVE-2026-24301

Microsoft Copilot Web: command injection

High8.8CVE-2026-24301 · Published Aug 18, 2026 · updated Sep 10, 2026

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Microsoft advisory

Affected versions

PackageAffectedFixed in
Copilot Web
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-77

More Microsoft advisories

All Microsoft
Advisory
Microsoft Fabric: path traversal
Critical9.9Aug 20
Microsoft Azure Data Factory: privilege escalation
Critical9.3Aug 20
Microsoft Windows Remote Help: uncontrolled search path
Medium5.5Aug 20
Microsoft Windows Remote Help: spoofing
High7.1Aug 20
Microsoft Windows App for Mac: out-of-bounds read
Medium6.5Aug 19
Microsoft Windows Telephony Service: race condition
High7.0Aug 19

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.