CVE-2026-26137 Microsoft 365 Copilot BizChat Elevation of Privilege Vulnerability

User avatar
admin Verified Great Britain
Site Admin
Posts: 22286
Joined: Wed Jun 11, 2025 9:20 pm

Awards

CVE-2026-26137 Microsoft 365 Copilot BizChat Elevation of Privilege Vulnerability

Post by admin Verified »

Server-side request forgery (ssrf) in Microsoft 365 Copilot's Business Chat allows an authorized attacker to elevate privileges over a network.

Source: https://msrc.microsoft.com/update-guide ... 2026-26137
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest