rootpwn

medium · CVSS v3 6.1

CVE-2026-55946

CVE-2026-55946 is a command injection vulnerability in Microsoft Copilot that can allow an unauthorized attacker to disclose information ove

Overview

CVE-2026-55946 is a command injection vulnerability in Microsoft Copilot that can allow an unauthorized attacker to disclose information over a network. It matters because Copilot may process user or external input in ways that could lead to unintended command execution or data exposure. Defenders should treat it as a medium-severity issue requiring prompt patching and input-handling review.

Description

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Impact

The primary impact is to confidentiality, as the vulnerability may allow network-based information disclosure. Integrity and availability impacts are not described in the provided summary. Users and organizations that expose Microsoft Copilot to untrusted input, external networks, or low-trust environments are most at risk. The issue is defensive in nature and should be addressed by reducing exposure and applying vendor controls.

Remediation

Apply the latest Microsoft security update or vendor-provided patch for Microsoft Copilot. Restrict network exposure of Copilot components and limit access to trusted users and networks. Enforce strict input validation and sanitization for any data passed to Copilot or related command-handling features. Review logging and monitoring for unusual command execution or information-disclosure activity. If the feature is not required, disable or isolate it until patched.

Risk context

The vulnerability is rated medium severity with a CVSS v3 score of 6.1. No EPSS score is provided, so urgency should be based on exposure, patch availability, and organizational risk tolerance. It should be prioritized as a standard patching item, with higher urgency if Copilot is exposed to untrusted input or external networks.

Affected products

  • Microsoft Copilot

Scores

Severity
medium
CVSS v2
5.4
CVSS v3
6.1
CVSS v4
EPSS

command-injection microsoft-copilot information-disclosure input-validation cve-2026-55946

← All CVEs