CVE-2026-85887

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

  • Published Sep 18, 2026
  • CVSS 7.7 high
  • 0.8% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-85887 at the National Vulnerability Database