VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-85887

CVE-2026-85887: Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose informat

Published Sep 18, 2026 CVSS 7.7

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

Affected AI Products

copilot
Get the weekly digest. Every Monday: top AI security stories of the week. Free.