Description
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
Published: 2026-07-24
Score: 9.9 Critical
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Deserialization of untrusted data in Microsoft 365 Copilot allows an authorized attacker to execute code over the network. This can lead to arbitrary code execution.

Affected Systems

Microsoft 365 Copilot. All installations of the product are potentially vulnerable until updated, as no version details are specified.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity and the EPSS score of 1% suggests a moderate probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attacker must possess authorized credentials and network connectivity to the Copilot service; without these, exploitation is unlikely. The flaw permits execution of arbitrary code over the network.

Generated by OpenCVE AI on August 3, 2026 at 20:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any Microsoft 365 Copilot update that addresses CVE-2026-50517.
  • Limit or disable Copilot functionality for users until a patch is confirmed deployed and review account permissions to ensure only essential users have access.
  • Continuously monitor logs for unexpected code execution attempts or anomalous activity.

Generated by OpenCVE AI on August 3, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
Title Microsoft M365 Copilot Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Copilot
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Copilot
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Copilot
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:21:31.337Z

Reserved: 2026-06-04T19:00:41.292Z

Link: CVE-2026-50517

cve-icon Vulnrichment

Updated: 2026-07-24T11:09:14.487Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T01:17:02.257

Modified: 2026-07-29T14:19:20.030

Link: CVE-2026-50517

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data