Description
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-17
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

This vulnerability arises from improper neutralization of special elements used in a command, permitting command injection that can lead to information disclosure. An attacker can exploit the flaw to retrieve sensitive data transmitted over the network. The weakness is classified primarily as a command injection problem, potentially exposing data that should remain confidential.

Affected Systems

The affected system is Microsoft 365 Copilot’s Business Chat service. No specific version information is provided, so all active instances of Business Chat are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 7.4 indicates a moderate to high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be over a network, as the description specifies disclosure over a network by an unauthorized attacker. No additional exploitation conditions are detailed in the provided information.

Generated by OpenCVE AI on September 18, 2026 at 23:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest security update for Microsoft 365 Copilot’s Business Chat as published by Microsoft.
  • Restrict network access to Business Chat services so that only trusted users and networks can connect, using firewall rules or conditional access policies.
  • Monitor system logs and network traffic for signs of command injection or unexpected data disclosures and investigate any anomalies promptly.

Generated by OpenCVE AI on September 18, 2026 at 23:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft 365 Copilot Chat
CPEs cpe:2.3:a:microsoft:365_copilot_chat:-:*:*:*:*:*:*:*
Vendors & Products Microsoft 365 Copilot Chat

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
Title Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Copilot Business Chat
Weaknesses CWE-77
CWE-923
CPEs cpe:2.3:a:microsoft:365_copilot_business_chat:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Copilot Business Chat
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Copilot Business Chat 365 Copilot Chat
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-07T15:00:02.585Z

Reserved: 2026-08-24T17:28:00.621Z

Link: CVE-2026-78501

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:30.502Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T23:18:45.770

Modified: 2026-10-07T14:11:24.353

Link: CVE-2026-78501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:15:17Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-923

    Improper Restriction of Communication Channel to Intended Endpoints