PT-2026-46402 · Microsoft · M365 Copilot

Guillermo Diaz

+2

·

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2026-45497

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-45497

Affected Products

M365 Copilot