CVE-2026-41106
Microsoft · Published July 2, 2026
9.3
CVSS v3.1
CRITICALPatch availableGet patch
Description
Microsoft 365 Copilot Elevation of Privilege Vulnerability. Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Affected Products
- Microsoft 365 Copilot
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C