rootpwn

critical · CVSS v3 9.9

CVE-2026-85885

CVE-2026-85885 is a critical command injection vulnerability in Microsoft 365 Copilot. It allows an authorized attacker to escalate privileg

Overview

CVE-2026-85885 is a critical command injection vulnerability in Microsoft 365 Copilot. It allows an authorized attacker to escalate privileges over a network. This matters because it could undermine tenant security controls and expand attacker access within Microsoft 365 environments.

Description

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

Impact

The vulnerability can affect confidentiality, integrity, and availability by enabling privilege escalation from an authorized account. Organizations using M365 Copilot are most at risk, particularly tenants with broad user access or elevated administrative roles. Successful exploitation could lead to unauthorized access to sensitive data, tampering with tenant settings, or disruption of services. Defenders should treat this as a high-priority identity and tenant security issue.

Remediation

Apply the latest Microsoft security update or vendor-provided fix for M365 Copilot as soon as it is available. Restrict M365 Copilot access to trusted users and apply least-privilege principles. Enforce multi-factor authentication, conditional access, and monitoring for anomalous privilege changes or administrative activity. If patching is delayed, consider disabling or limiting Copilot features for affected users and increase audit log review.

Risk context

CVSS v3 is 9.9, indicating critical severity. No EPSS score is provided, so urgency should be driven by exposure, tenant criticality, and patch availability. Organizations with M365 Copilot enabled should prioritize validation and remediation.

Affected products

  • Microsoft 365 Copilot

Scores

Severity
critical
CVSS v2
9
CVSS v3
9.9
CVSS v4
EPSS

command-injection privilege-escalation microsoft-365 copilot critical tenant-security

← All CVEs