Microsoft 365 Copilot Privilege Escalation Vulnerability
Vulnerability
A vulnerability allowing URL redirection to untrusted sites ('open redirect') has been identified in Microsoft 365 Copilot. This issue allows an unauthorized attacker to elevate privileges over a network. The vulnerability is present in all versions of Microsoft 365 Copilot.
Impact
Exploitation of this vulnerability could lead to unauthorized privilege escalation.
Added: Apr 23, 2026, 11:09 PM
Updated: Apr 23, 2026, 11:09 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.2exploitability
6.2remediation
0.0relevance
6.5threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
