CyberRota Analysis
AI-GeneratedM365 Copilot is vulnerable to a command injection flaw that allows authorized attackers to execute arbitrary commands, potentially leading to privilege escalation across the network. This critical vulnerability, with a CVSS score of 9.9, poses significant risks to organizations utilizing M365 Copilot, making it imperative for security teams to prioritize immediate remediation efforts.
CVE
CVE-2026-85885
Severity
CRITICAL
CVSS
9.9
EPSS
0.72%
Original NVD Description
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
Related CVEs
Other vulnerabilities affecting the same vendor(s)