Description
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-07-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw, categorized as CWE‑284, that allows an unauthorized attacker to elevate privileges in Microsoft 365 Copilot for iOS when communicating over a network. An attacker who can reach the Copilot service can gain higher‑level permissions than normally permitted, potentially enabling unauthorized actions within the application.

Affected Systems

The affected product is Microsoft 365 Copilot for iOS. The vulnerability applies to all deployed instances of the app until a patch is applied; no specific version range is indicated.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. The EPSS score of less than 1% indicates a low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based adversary who can send or intercept requests to the Copilot service to manipulate privilege levels.

Generated by OpenCVE AI on July 31, 2026 at 06:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft update for Microsoft 365 Copilot for iOS that addresses CVE‑2026‑58617.
  • If an update is not yet available, limit the execution of privileged actions in the app to authenticated or trusted users until the patch is installed.
  • Monitor network traffic and application logs for abnormal privilege requests and investigate suspicious activity promptly.

Generated by OpenCVE AI on July 31, 2026 at 06:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft 365 Copilot Ios
Vendors & Products Microsoft 365 Copilot Ios

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
Title M365 Copilot for iOS Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft 365 Copilot Ios
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:365_copilot_iOS:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Copilot Ios
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Copilot Ios 365 Copilot Ios
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:27:48.921Z

Reserved: 2026-07-01T18:03:43.126Z

Link: CVE-2026-58617

cve-icon Vulnrichment

Updated: 2026-07-14T18:27:06.837Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:15:04Z

Weaknesses