High severity7.7NVD Advisory· Published Sep 18, 2026
CVE-2026-85887
CVE-2026-85887
Description
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.