Skip to content
CVSS 9.3 · CRITICAL

CVE-2026-33102

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

View on NVD

Analysis

Microsoft 365 Copilot is vulnerable to a critical URL redirection flaw that allows attackers to elevate privileges over the network. Organizations using Copilot for Microsoft 365 should ensure they are running the latest versions to prevent unauthorized access to sensitive corporate resources.

Severity

Score: 9.3(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: REQUIRED
S: CHANGED
C: HIGH
I: HIGH
A: NONE
Weakness (CWE): CWE-601

EPSS

Probability of exploitation (next 30 days): 0.0005 (0.0%)
Percentile: 15.0%
EPSS: 2026-05-06

Affects

microsoft:365_copilot

Technical description

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Published: 4/23/2026, 10:16:37 PM
Last modified: 4/29/2026, 7:04:21 PM

References

HomeEventsBlogResourcesTeam