CVE-2026-26133
Published: Mar 13, 2026
Modified: Apr 14, 2026
CVSS v3.1
7.1
Description
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
| Vendor | Product | Versions |
|---|---|---|
Microsoft | Microsoft 365 Copilot for Android | affected 1.0 - < 16.0.19815.10000 |
Microsoft | Microsoft 365 Copilot for iOS | affected 1.0 - < 2.107.2 |
Microsoft | Microsoft Edge for Android | affected 1.0.0 - < 145.3800.99 |
Microsoft | Microsoft Edge for iOS | affected 1.0.0.0 - < 145.3800.99 |
Microsoft | Microsoft Excel for Android | affected 16.0.0.0 - < 16.0.19822.20038 |
Microsoft | Microsoft Excel for iOS | affected 1.0 - < 2.106.26020617 |
Microsoft | Microsoft Loop for iOS | affected 2.0.0 - < 2.106.26020617 |
Microsoft | Microsoft OneNote | affected 1.0.0 - < 2.106.26020617 |
Microsoft | Microsoft OneNote for Android | affected 16.0.1 - < 16.0.19725.20142 |
Microsoft | Microsoft Outlook for Android | affected 1.0 - < 5.2605 |
Microsoft | Microsoft Outlook for iOS | affected 1.0.0 - < 5.2605 |
Microsoft | Microsoft Outlook for Mac | affected 1.0.0 - < 5.2605 |
Microsoft | Microsoft PowerBI for Android | affected 2.0.0 - < 2.2.260210.21290750 |
Microsoft | Microsoft PowerBI for iOS | affected 1.0.0 - < 1.2.260302.2193910 |
Microsoft | Microsoft PowerPoint for Android | affected 16.0.0.0 - < 16.0.19822.20038 |
Microsoft | Microsoft PowerPoint for iOS | affected 1.0 - < 2.106.26020617 |
Microsoft | Microsoft Teams for Android | affected 1.0.0 - < 1.0.0.2026043102 |
Microsoft | Microsoft Teams for iOS | affected 2.0.0 - < 8.3.1 |
Microsoft | Microsoft Word for Android | affected 16.0.0.0 - < 16.0.19822.20038 |
Microsoft | Microsoft Word for iOS | affected 2.0.0 - < 2.106.26020617 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now