CyberRota Analysis
AI-GeneratedOutlook Copilot is vulnerable to command injection due to improper handling of special elements, enabling an authorized attacker to manipulate commands over the network. This could lead to unauthorized data access or modification, posing a risk to the integrity of communications. Organizations using Outlook Copilot should prioritize patching this vulnerability to safeguard their systems against potential exploitation.
CVE
CVE-2026-55145
Severity
MEDIUM
CVSS
6.3
EPSS
0.37%
Original NVD Description
Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.
Related CVEs
Other vulnerabilities affecting the same vendor(s)