Description
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-17
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from improper neutralization of special elements used in a command, allowing command injection in Microsoft Copilot. This flaw lets an unauthorized attacker issue crafted instructions that the Copilot backend executes, leading to disclosure of sensitive data or system state over the network. The impact is a loss of confidentiality for any information that the affected service handles.

Affected Systems

Microsoft Copilot deployments are impacted. All current versions of the Copilot service that have not received the Microsoft patch are vulnerable. Specific version numbers are not listed, so any supported release should be treated as at risk until an official update is applied.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1 % shows a low probability of exploitation at the time of analysis. Because the flaw is not yet listed in CISA KEV, it has not been widely exploited, yet the attack appears to require an attacker to send a crafted command to the Copilot service over a network, implying a remote attack vector. The combination of moderate severity and low exploitation likelihood suggests a moderate risk that warrants prompt mitigation to avoid potential data leakage.

Generated by OpenCVE AI on September 18, 2026 at 23:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Microsoft‑provided update that patches the command injection flaw in Copilot.
  • Configure network policies or firewall rules to allow Copilot API traffic only from trusted, authenticated sources.
  • Implement input validation or a command whitelist in any custom scripts or integrations that pass user data to Copilot, rejecting special command characters.

Generated by OpenCVE AI on September 18, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:copilot:-:*:*:*:*:*:*:*

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
Title Microsoft Copilot Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft copilot
Weaknesses CWE-77
CPEs cpe:2.3:a:microsoft:copilot:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft copilot
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Copilot
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-08T18:12:07.070Z

Reserved: 2026-06-17T17:37:17.983Z

Link: CVE-2026-55946

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:26.268Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T23:17:46.687

Modified: 2026-09-25T20:32:07.073

Link: CVE-2026-55946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:15:17Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')