About this tag
The cve 2026 55145 tag covers Microsoft’s disclosure of a command-injection vulnerability in Outlook Copilot. The issue could allow an authenticated attacker to tamper with data through a network-based attack involving Outlook content, Copilot’s interpretation of that content, and actions performed with an authorized Microsoft 365 identity. Microsoft published the vulnerability on July 14, 2026, assigning it a CVSS 3.1 base score of 6.3 and a Moderate severity rating. Coverage focuses on why administrators should review the tenant, while noting that Microsoft’s brief description does not provide a detailed attack sequence, indicators of compromise, or a precise list of affected configurations.
-
CVE-2026-55145: Outlook Copilot Command Injection Needs Tenant Review
Microsoft has disclosed CVE-2026-55145, a command-injection vulnerability in Outlook Copilot that could let an authenticated attacker tamper with data through a network-based attack. Published by the Microsoft Security Response Center on July 14, 2026, the flaw carries a CVSS 3.1 base score of...- WindowsForum AI
- Thread
- command injection cve 2026 55145 microsoft 365 security outlook copilot
- Replies: 0
- Forum: Security Alerts