ZeroHour

CVE-2026-85885

mass

Command Injection Privilege Escalation in Microsoft 365 Copilot

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-85885 is a command injection flaw (CWE-77) in Microsoft 365 Copilot in which special elements in user-supplied input are improperly neutralized before being passed to a command interpreter. An authorized, low-privileged user can trigger it over the network with crafted input and no user interaction or special conditions. Successful exploitation elevates the attacker's privileges, with high impact to confidentiality, integrity, and availability, and the changed scope in the CVSS vector indicates impact can extend beyond the initially compromised component. Any organization whose users have Microsoft 365 Copilot enabled is in scope, since the flaw resides in Microsoft's cloud service rather than a locally installed product. There is currently no evidence of exploitation in the wild, no public proof-of-concept, and the flaw is not listed in CISA's KEV catalog.

What to do: Check the MSRC advisory for CVE-2026-85885 and confirm your tenant has received Microsoft's server-side update, since fixes for the Copilot cloud service are deployed by Microsoft rather than patched locally. In the interim, limit Copilot licenses and access to users who need them and review Microsoft 365 audit logs for unusual privileged actions originating from low-privileged accounts. If the advisory lists any client-side component version to update, apply it promptly.

Affected
Microsoft 365 Copilot
Estimated exposure
mass≈100M users / tens of millions of paid enterprise seats (Microsoft-reported M365 Copilot monthly active user base) — Microsoft 365 Copilot is a cloud service with very broad enterprise adoption (Microsoft has publicly reported a monthly active user base on the order of 100 million, including the majority of the Fortune 500), and every tenant with Copilot…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft patched a CVSS 10.0 missing-authentication privilege escalation flaw, CVE-2026-85889, in Azure AI Foundry, already fully mitigated server-side.

Microsoft fixed CVE-2026-85889, a CVSS 10.0 missing-authentication flaw in Azure AI Foundry (Microsoft Foundry) that allows unauthorized attackers to elevate privileges over a network, credited to researcher Rémy Marot. No exploitation in the wild was reported, and Microsoft says these cloud flaws are fully mitigated with no customer action required. The same effort covered CVE-2026-85885 (CVSS 9.9 command injection in Microsoft 365 Copilot), CVE-2026-85878 (CVSS 9.9 Azure Database for PostgreSQL), and CVE-2026-87701 (CVSS 9.6 Azure Cosmos DB). Out-of-band Windows 11 26H1 updates (KB5129194) also address local privilege escalation flaws CVE-2026-62721 and CVE-2026-85921.

Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges

Microsoft patched CVE-2026-85889 (CVSS 10.0), a missing-auth flaw in Azure AI Foundry enabling unauthenticated network privilege escalation; no exploitation observed.

CVE-2026-85889, rated 10.0, stems from a missing authentication check (CWE-306) in Azure AI Foundry, letting unauthenticated attackers abuse a backend function and bypass access controls. Microsoft deployed a server-side fix, so no customer action is required, and reports no active exploitation or public PoC. The advisory window also included CVE-2026-85885 in Microsoft 365 Copilot and CVE-2026-85878 in Azure Database for PostgreSQL, both rated 9.9.