Command Injection in Microsoft 365 Copilot for iOS and Microsoft 365 Copilot for Android - CVE-2026-48561
Published: July 14, 2026
Vulnerability identifier: #VU137534
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-48561
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands on the system.
The vulnerability exists due to insufficient input validation in Microsoft Copilot. A remote attacker can host a malicious website and execute arbitrary commands on the target system.
Affected software
Microsoft 365 Copilot for iOS
Microsoft 365 Copilot for Android
Microsoft 365 Copilot for Android
How to mitigate CVE-2026-48561
Install updates from vendor's website.