VulnWatch VulnWatch
← Back to dashboard
Critical nvd · CVE-2026-41106

CVE-2026-41106: Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege

Published Jul 2, 2026 CVSS 9.3

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Affected AI Products

copilot
Get the weekly digest. Every Monday: top AI security stories of the week. Free.