Description
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-08-06
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper authorization in Microsoft Copilot Cowork allows an unauthorized attacker to elevate privileges over a network, potentially gaining full control of the application and its underlying data. The vulnerability is a classic access control weakness (CWE-285) and can lead to unauthorized system access, data exposure, or manipulation by an attacker who originally had no privileges.

Affected Systems

Microsoft Copilot Cowork instances are affected; without version details, all deployments that have not applied the latest security updates may be vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity. The EPSS score of 0.0039 confirms a very low but non-zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve network access to the Copilot Cowork environment, and an attacker would need to exploit the flawed authorization checks to elevate privileges. Given the high score, the risk is significant, especially in unprotected or poorly segmented environments.

Generated by OpenCVE AI on August 13, 2026 at 10:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any available Microsoft Copilot Cowork security updates to remove the authorization flaw.
  • Restrict network access to Copilot Cowork instances by configuring firewall rules or network segmentation to limit exposure to untrusted networks.
  • Review and enforce least privilege role assignments within Copilot Cowork, ensuring users only have the permissions required for their job functions.

Generated by OpenCVE AI on August 13, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Power Apps Elevation of Privilege Vulnerability Copilot Cowork Elevation of Privilege Vulnerability
First Time appeared Microsoft copilot Cowork
CPEs cpe:2.3:a:microsoft:power-apps:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:copilot_cowork:*:*:*:*:*:*:*:*
Vendors & Products Microsoft copilot Cowork

Fri, 07 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Power Apps Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft power-apps
Weaknesses CWE-285
CPEs cpe:2.3:a:microsoft:power-apps:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft power-apps
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Copilot Cowork Power-apps Power Apps
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-26T23:20:50.074Z

Reserved: 2026-07-02T16:05:24.069Z

Link: CVE-2026-59118

cve-icon Vulnrichment

Updated: 2026-08-07T00:56:37.925Z

cve-icon NVD

Status : Modified

Published: 2026-08-07T00:16:33.923

Modified: 2026-08-11T18:17:39.147

Link: CVE-2026-59118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:45:04Z

Weaknesses