PT-2026-34760 · Microsoft · M365 Copilot

Bushra Aloraini

+2

·

Published

2026-04-23

·

Updated

2026-04-25

·

CVE-2026-33102

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Microsoft 365 Copilot (affected versions not specified)
Description An open redirect allows an unauthorized attacker to redirect users to untrusted sites, which can lead to elevation of privilege over a network and risk to user accounts. This issue is under active exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Open Redirect

Weakness Enumeration

Related Identifiers

BDU:2026-06837
CVE-2026-33102

Affected Products

M365 Copilot