critical · CVSS v3 9.9
CVE-2026-85885
CVE-2026-85885 is a critical command injection vulnerability in Microsoft 365 Copilot. It allows an authorized attacker to escalate privileg
Overview
CVE-2026-85885 is a critical command injection vulnerability in Microsoft 365 Copilot. It allows an authorized attacker to escalate privileges over a network. This matters because it could undermine tenant security controls and expand attacker access within Microsoft 365 environments.
Description
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
Impact
The vulnerability can affect confidentiality, integrity, and availability by enabling privilege escalation from an authorized account. Organizations using M365 Copilot are most at risk, particularly tenants with broad user access or elevated administrative roles. Successful exploitation could lead to unauthorized access to sensitive data, tampering with tenant settings, or disruption of services. Defenders should treat this as a high-priority identity and tenant security issue.
Remediation
Apply the latest Microsoft security update or vendor-provided fix for M365 Copilot as soon as it is available. Restrict M365 Copilot access to trusted users and apply least-privilege principles. Enforce multi-factor authentication, conditional access, and monitoring for anomalous privilege changes or administrative activity. If patching is delayed, consider disabling or limiting Copilot features for affected users and increase audit log review.
Risk context
CVSS v3 is 9.9, indicating critical severity. No EPSS score is provided, so urgency should be driven by exposure, tenant criticality, and patch availability. Organizations with M365 Copilot enabled should prioritize validation and remediation.
Affected products
- Microsoft 365 Copilot
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 9.9
- CVSS v4
- —
- EPSS
- —