rootpwn

high · CVSS v3 7.4

CVE-2026-78501

CVE-2026-78501 is a high-severity command injection vulnerability in Microsoft 365 Copilot's Business Chat. It can allow an unauthorized att

Overview

CVE-2026-78501 is a high-severity command injection vulnerability in Microsoft 365 Copilot's Business Chat. It can allow an unauthorized attacker to disclose information over a network. It matters because Microsoft 365 Copilot Business Chat may process user input in a way that can expose sensitive tenant or user data.

Description

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.

Impact

The primary impact is confidentiality, with potential disclosure of information over a network. Organizations using Microsoft 365 Copilot Business Chat are most exposed, especially users with access to sensitive business data. Integrity and availability impacts are not described in the provided summary, but command injection can sometimes lead to broader misuse if additional capabilities are available. Defenders should treat this as a data-exposure risk for cloud collaboration and AI-assisted chat workloads.

Remediation

Apply the latest Microsoft 365 Copilot updates or vendor-provided patch as soon as available. Restrict Business Chat access to users who require it and enforce least-privilege roles. Review and limit data sources, connectors, and integrations exposed to Copilot Business Chat. Enable and monitor relevant Microsoft 365 audit logs, sign-in logs, and application activity for unusual access or data retrieval. If the feature is not required, disable or defer rollout until patched. Strengthen conditional access, MFA, and network egress controls to reduce the risk of lateral movement or data exfiltration.

Affected products

  • Microsoft 365 Copilot
  • Microsoft 365 Copilot Business Chat

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.4
CVSS v4
EPSS

← All CVEs