CVE-2026-26133

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:excel:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:excel:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:loop:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:onenote:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:onenote:-:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:outlook:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:outlook:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:outlook:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:power_bi:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:power_bi:-:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:teams:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:word:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:word:*:*:*:*:*:android:*:*

History

07 Apr 2026, 14:54

Type Values Removed Values Added
CPE cpe:2.3:a:microsoft:powerbi:-:*:*:*:*:iphone_os:*:* cpe:2.3:a:microsoft:power_bi:-:*:*:*:*:iphone_os:*:*

07 Apr 2026, 14:29

Type Values Removed Values Added
First Time Microsoft excel
Microsoft outlook
Microsoft onenote
Microsoft 365 Copilot
Microsoft powerpoint
Microsoft
Microsoft edge
Microsoft power Bi
Microsoft loop
Microsoft word
Microsoft powerbi
Microsoft teams
CPE cpe:2.3:a:microsoft:outlook:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:outlook:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:onenote:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:power_bi:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:outlook:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:excel:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:word:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:teams:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:powerbi:-:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:excel:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:onenote:-:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:word:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:loop:*:*:*:*:*:iphone_os:*:*
Summary
  • (es) La inyección de comandos de IA en M365 Copilot permite a un atacante no autorizado divulgar información a través de una red.
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26133 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26133 - Vendor Advisory
CWE CWE-77

16 Mar 2026, 14:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:18

Updated : 2026-04-09 18:16


NVD link : CVE-2026-26133

Mitre link : CVE-2026-26133

CVE.ORG link : CVE-2026-26133


JSON object : View

Products Affected

microsoft

  • 365_copilot
  • power_bi
  • edge
  • excel
  • powerpoint
  • teams
  • outlook
  • onenote
  • word
  • loop
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')