CVE-2026-26133 PUBLISHED

M365 Copilot Information Disclosure Vulnerability

Assigner: microsoft
Reserved: 11.02.2026 Published: 13.03.2026 Updated: 13.03.2026

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C
CVSS Score: 7.1

Product Status

Vendor Microsoft
Product Microsoft 365 Copilot for Android
Versions
  • affected from 1.0 to 16.0.19815.10000 (excl.)
Vendor Microsoft
Product Microsoft 365 Copilot for iOS
Versions
  • affected from 1.0 to 2.107.2 (excl.)
Vendor Microsoft
Product Microsoft Edge for Android
Versions
  • affected from 1.0.0 to 145.3800.99 (excl.)
Vendor Microsoft
Product Microsoft Edge for iOS
Versions
  • affected from 1.0.0.0 to 145.3800.99 (excl.)
Vendor Microsoft
Product Microsoft Excel for Android
Versions
  • affected from 16.0.0.0 to 16.0.19822.20038 (excl.)
Vendor Microsoft
Product Microsoft Excel for iOS
Versions
  • affected from 1.0 to 2.106.26020617 (excl.)
Vendor Microsoft
Product Microsoft Loop for iOS
Versions
  • affected from 2.0.0 to 2.106.26020617 (excl.)
Vendor Microsoft
Product Microsoft OneNote
Versions
  • affected from 1.0.0 to 2.106.26020617 (excl.)
Vendor Microsoft
Product Microsoft OneNote for Android
Versions
  • affected from 16.0.1 to 16.0.19725.20142 (excl.)
Vendor Microsoft
Product Microsoft Outlook for Android
Versions
  • affected from 1.0 to 5.2605 (excl.)
Vendor Microsoft
Product Microsoft Outlook for iOS
Versions
  • affected from 1.0.0 to 5.2605 (excl.)
Vendor Microsoft
Product Microsoft Outlook for Mac
Versions
  • affected from 1.0.0 to 5.2605 (excl.)
Vendor Microsoft
Product Microsoft PowerBI for Android
Versions
  • affected from 2.0.0 to 2.2.260210.21290750 (excl.)
Vendor Microsoft
Product Microsoft PowerBI for iOS
Versions
  • affected from 1.0.0 to 1.2.260302.2193910 (excl.)
Vendor Microsoft
Product Microsoft PowerPoint for Android
Versions
  • affected from 16.0.0.0 to 16.0.19822.20038 (excl.)
Vendor Microsoft
Product Microsoft PowerPoint for iOS
Versions
  • affected from 1.0 to 2.106.26020617 (excl.)
Vendor Microsoft
Product Microsoft Teams for Android
Versions
  • affected from 1.0.0 to 1.0.0.2026043102 (excl.)
Vendor Microsoft
Product Microsoft Teams for iOS
Versions
  • affected from 2.0.0 to 8.3.1 (excl.)
Vendor Microsoft
Product Microsoft Word for Android
Versions
  • affected from 16.0.0.0 to 16.0.19822.20038 (excl.)
Vendor Microsoft
Product Microsoft Word for iOS
Versions
  • affected from 2.0.0 to 2.106.26020617 (excl.)

References

Problem Types