CVE-2026-24301
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- EPSS probability
- 2.66%
- CWE
- CWE-77
- Published
- 2026-08-18
- Last modified
- 2026-09-16
Affected products
- Microsoft Copilot Web
Weakness type
Related vulnerabilities
- CVE-2026-47670 — DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
- CVE-2026-86152 — Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection
- CVE-2026-82971 — QVidium Opera11 CGI Script net_tr.cgi command injection
- CVE-2026-72869 — Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE
- CVE-2026-72736 — Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCE
- CVE-2026-72735 — Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution
- CVE-2026-54680 — Logging operator has Fluentd configuration injection that allows remote code execution
- CVE-2026-28672 — Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder