Microsoft 365 Copilot Elevation of Privilege Vulnerability

Date Jul 2, 2026
Type Patch Tuesday
Signal Critical vendor advisory
Vendor / Product Microsoft ยท M365 Copilot
CVE CVE-2026-41106
Critical vendor advisory CVE-2026-41106

Summary

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Why it matters

Microsoft published this item through its Security Update Guide, making it part of Patch Tuesday triage for affected Windows, cloud, or application estates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-41106. Confirm whether M365 Copilot is deployed, then apply the current security update or documented mitigation. CVSS score: 9.3.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.