External risk intelligence

M365 Copilot Command Injection Privilege Escalation

CVE advisorySeverity: HIGH (CVSS 8.8)

CVE-2026-85885

M365 Copilot is a cloud-based productivity assistant integrated into enterprise environments. While it is accessed via network interfaces, it is typically used within authenticated, internal-facing business ecosystems rather than as a public-facing internet service, making broad public internet exposure possible but not the standard deployment pattern.

Command Injection

Microsoft 365 Copilot

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in M365 Copilot that could allow an attacker to gain elevated privileges over the network. This type of issue, known as command injection, means that specially crafted inputs could be used to execute unauthorized commands. The main concern is to confirm if our specific usage of M365 Copilot is exposed and relevant.

  • Attackers could gain elevated privileges.
  • Confirm if M365 Copilot usage is exposed.
  • Assess relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with basic access to M365 Copilot can exploit this vulnerability by sending specially crafted commands over the network. This allows them to inject their own commands, leading to elevated privileges within the system.

  • Requires authenticated access.
  • Triggered by sending special commands.
  • Results in privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

An authorized attacker could exploit this vulnerability to execute arbitrary commands, potentially leading to privilege escalation over a network when supported by the advisory. This could impact the confidentiality, integrity, and availability of the system.

  • System commands and data.
  • Network access with limited privileges.
  • Unauthorized control and data access.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this command injection vulnerability in M365 Copilot, the primary responsibility likely falls to the platform or application owners who manage the deployment and integration of Copilot within the organization. The first critical step is to identify all instances of M365 Copilot, determine their network reachability and business criticality, and locate the accountable personnel for each instance to plan a coordinated remediation effort.

  • Platform or application owners should address.
  • Verify Copilot instances and criticality.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is M365 Copilot?

M365 Copilot is a cloud-based AI productivity assistant integrated into the Microsoft 365 ecosystem. It processes data and executes tasks across workplace applications like Word, Excel, and Teams to enhance user efficiency. Organizations deploy it within their business environments to provide intelligent automation and insights based on organizational data.

What does CVE-2026-85885 mean by command injection?

This vulnerability is classified as CWE-77, which involves improper neutralization of special elements in a command. Essentially, the software fails to properly filter user-provided input before processing it. An attacker can manipulate this input to inject unauthorized, malicious commands that the system then executes with elevated permissions, bypassing intended security controls.

How is this command injection vulnerability triggered?

An attacker triggers this bug by sending specially crafted commands through the network to the M365 Copilot interface. It is important to note that this requires the attacker to already have authenticated access to the system. Simply browsing to a page or interacting with the service anonymously does not trigger the vulnerability, as it relies on the processing of specific, malicious input strings.

Is my organization at risk from CVE-2026-85885?

According to Halo Surface Signal, M365 Copilot is typically used within authenticated, internal-facing business ecosystems. While the vulnerability technically has a network attack vector, it is rarely exposed directly as a public-facing internet service. Organizations should evaluate their specific deployment to determine if the service is reachable by unauthorized entities outside their controlled environment.

What should I do if I use M365 Copilot?

The first step is to coordinate with your platform or application owners to identify all active instances of M365 Copilot within your organization. Evaluate the business criticality and network accessibility of these instances. Since this is a cloud-based service, focus your response on identifying the accountable personnel who can track official updates and remediation guidance provided by Microsoft.

References