PT-2026-26355 · Microsoft · M365 Copilot

Michael Van Leeuwen

·

Publicado

2026-03-19

·

Atualizado

2026-03-22

·

CVE-2026-26137

CVSS v3.1

9.9

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Microsoft 365 Copilot's Business Chat (affected versions not specified)
Description An authorized attacker can elevate privileges over a network due to a server-side request forgery (SSRF) issue in Microsoft 365 Copilot's Business Chat. Server-side request forgery occurs when an application allows an attacker to make requests to unintended locations. This can potentially lead to unauthorized access to internal resources or data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-03516
CVE-2026-26137

Produtos afetados

M365 Copilot