Description
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
Published: 2026-08-20
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery that permits an authorized attacker to instruct Microsoft Copilot in Azure to retrieve internal network resources, potentially exposing sensitive data. This weakness follows CWE‑918 and results in unauthorized disclosure of information accessible to the service.

Affected Systems

Microsoft Copilot in Azure, all deployed instances—specific vulnerable versions are not enumerated in the advisories. Any environment running the service is potentially affected.

Risk and Exploitability

The CVSS score of 7.7 denotes high severity, yet the EPSS score is currently unavailable and the vulnerability has not been listed in CISA's KEV catalog. The attack vector is a server‑side request forgery accessible by an authenticated user; once exploited, the attacker can force the service to contact internal endpoints, leading to data disclosure or facilitating further lateral movement. The risk remains significant for organizations that have not applied any vendor‑issued fix.

Generated by OpenCVE AI on August 21, 2026 at 00:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install any Microsoft update that addresses this SSRF vulnerability in Copilot in Azure.
  • Restrict the service's outbound traffic to only approved endpoints using firewall or network group rules.
  • Enable logging of outbound requests and actively monitor for anomalous or unexpected traffic patterns that may indicate SSRF activity.

Generated by OpenCVE AI on August 21, 2026 at 00:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft azure Copilot
CPEs cpe:2.3:a:microsoft:azure_copilot:-:*:*:*:*:*:*:*
Vendors & Products Microsoft azure Copilot

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
Title Microsoft Copilot in Azure Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft microsoft Copilot In Azure
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:microsoft_copilot_in_azure:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft microsoft Copilot In Azure
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Copilot Microsoft Copilot In Azure
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:38:39.370Z

Reserved: 2026-08-03T22:51:46.191Z

Link: CVE-2026-69855

cve-icon Vulnrichment

Updated: 2026-08-21T15:31:52.558Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:18:01.003

Modified: 2026-09-08T18:14:37.843

Link: CVE-2026-69855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:00:30Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)