rootpwn

high · CVSS v3 7.7

CVE-2026-85887

CVE-2026-85887 is a high-severity permission misconfiguration in Microsoft 365 Copilot. It can allow an authorized attacker to disclose info

Overview

CVE-2026-85887 is a high-severity permission misconfiguration in Microsoft 365 Copilot. It can allow an authorized attacker to disclose information over a network. It matters because it may expose sensitive tenant or user data if Copilot resources are over-permissioned.

Description

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

Impact

The primary impact is confidentiality, with potential disclosure of sensitive information accessible through M365 Copilot. Integrity and availability impact appear limited based on the description. Impacted parties include Microsoft 365 tenants, Copilot users, and administrators responsible for Copilot resource permissions. Risk is elevated where sensitive data is accessible to broadly authorized users or service accounts.

Remediation

Apply the relevant Microsoft security update or vendor guidance when available. Review and correct permission assignments for M365 Copilot resources using least privilege. Enforce MFA, conditional access, and role-based access controls for users and service accounts that can access Copilot. Audit sign-in and application logs for anomalous access to Copilot-related resources. Restrict network access to Copilot resources where feasible and disable Copilot for users or workloads that do not require it.

Risk context

The reported CVSS v3 score is 7.7, indicating high severity. No EPSS value is provided. Defenders should prioritize remediation if M365 Copilot is deployed and sensitive data is accessible to authorized users or service accounts.

Affected products

  • Microsoft 365 Copilot
  • Microsoft 365

Scores

Severity
high
CVSS v2
6.8
CVSS v3
7.7
CVSS v4
EPSS

M365 Copilot permission misconfiguration CVE-2026-85887 Microsoft 365 confidentiality high severity

← All CVEs