CVE-2026-41106
Critical · CVSS 9.3Microsoft 365 Copilot — Open Redirect (URL Redirection to Untrusted Site) leading to Privilege Escalation
- CVSS
- 9.3
- nvd
- EPSS
- 0.54%
- 42th pct
- KEV
- No
- Class
- other
- CWE-601
Description
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Search profile — drives PoC discovery
Symbols M365 Copilotopen redirectredirect_uriurl redirectionprivilege escalationuntrusted siteCVE-2026-41106
Keywords CVE-2026-41106M365 Copilot open redirectMicrosoft 365 Copilot open redirectCopilot privilege escalationCWE-601 M365Microsoft Copilot URL redirect exploitM365 Copilot PoC
Versions: <UNKNOWN>
References
Status: enriched · ingested 2026-07-07T18:00:32.000Z · profiled 2026-07-07T18:30:32.000Z