CVE-2026-50517

Summary

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft 365 Copilot-affected

Weaknesses

  • CWE-502: CWE-502: Deserialization of Untrusted Data

References