AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
References
| Link | Resource |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26133 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
07 Apr 2026, 14:54
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:microsoft:power_bi:-:*:*:*:*:iphone_os:*:* |
07 Apr 2026, 14:29
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Microsoft excel
Microsoft outlook Microsoft onenote Microsoft 365 Copilot Microsoft powerpoint Microsoft Microsoft edge Microsoft power Bi Microsoft loop Microsoft word Microsoft powerbi Microsoft teams |
|
| CPE | cpe:2.3:a:microsoft:outlook:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:outlook:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:edge:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:onenote:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:power_bi:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:outlook:-:*:*:*:*:macos:*:* cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:excel:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:word:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:teams:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:powerbi:-:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:excel:*:*:*:*:*:android:*:* cpe:2.3:a:microsoft:onenote:-:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:word:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:loop:*:*:*:*:*:iphone_os:*:* |
|
| Summary |
|
|
| References | () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26133 - Vendor Advisory | |
| CWE | CWE-77 |
16 Mar 2026, 14:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 14:18
Updated : 2026-04-09 18:16
NVD link : CVE-2026-26133
Mitre link : CVE-2026-26133
CVE.ORG link : CVE-2026-26133
JSON object : View
Products Affected
microsoft
- 365_copilot
- power_bi
- edge
- excel
- powerpoint
- teams
- outlook
- onenote
- word
- loop
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
