CyberICT

CVE-2026-41106

Microsoft · Published July 2, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Microsoft 365 Copilot Elevation of Privilege Vulnerability. Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Affected Products

  • Microsoft 365 Copilot

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C