CVSS 9.3 · CRITICAL
CVE-2026-33102
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
View on NVDAnalysis
Microsoft 365 Copilot is vulnerable to a critical URL redirection flaw that allows attackers to elevate privileges over the network. Organizations using Copilot for Microsoft 365 should ensure they are running the latest versions to prevent unauthorized access to sensitive corporate resources.
Severity
Score: 9.3(CRITICAL)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NAV: NETWORK
AC: LOW
PR: NONE
UI: REQUIRED
S: CHANGED
C: HIGH
I: HIGH
A: NONE
Weakness (CWE):
CWE-601EPSS
Probability of exploitation (next 30 days): 0.0005 (0.0%)
Percentile: 15.0%
EPSS: 2026-05-06
Affects
microsoft:365_copilotTechnical description
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Published: 4/23/2026, 10:16:37 PM
Last modified: 4/29/2026, 7:04:21 PM