Description
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
Published: 2026-09-17
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

The vulnerability is an incorrect assignment of permissions to a critical resource in Microsoft 365 Copilot, which enables an authorized attacker to disclose sensitive information over the network. Based on the description, it is inferred that the flaw does not involve code execution or denial of service; it simply allows the exploitation of an existing access privilege to read confidential data that should be protected. The weakness is tied to incorrect permission handling (CWE‑732).

Affected Systems

Microsoft 365 Copilot is affected. No specific version or build details are provided, so any deployed instance of Copilot may be vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity, but the EPSS score of less than 1% suggests a low likelihood that exploitation is already occurring in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation. Based on the description, the likely attack vector is an authenticated attacker who already has legitimate access to the Copilot environment; there is no remote exploitation vector. Consequently, the risk is primarily to internal users who possess valid credentials, and the compromise would result in unwanted disclosure of confidential corporate data.

Generated by OpenCVE AI on September 19, 2026 at 00:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Microsoft 365 Copilot update or patch released through the Microsoft Security Response Center.
  • Review and enforce least‑privilege permissions for critical resources within Copilot to prevent over‑privileged access.
  • Implement monitoring of Copilot logs and audit trails to detect anomalous data disclosure attempts and investigate any unauthorized access.

Generated by OpenCVE AI on September 19, 2026 at 00:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:365_copilot:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
Title M365 Copilot Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Copilot
Weaknesses CWE-732
CPEs cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Copilot
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Copilot
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-08T18:20:40.346Z

Reserved: 2026-09-04T18:18:19.327Z

Link: CVE-2026-85887

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:47.122Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T00:17:47.920

Modified: 2026-09-28T18:37:31.143

Link: CVE-2026-85887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:15:13Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource