CVE-2026-85887 Overview
CVE-2026-85887 is an information disclosure vulnerability in Microsoft 365 Copilot caused by incorrect permission assignment for a critical resource. An authenticated attacker with low privileges can exploit the flaw over a network to access data outside their authorization boundary. The weakness maps to [CWE-732] Incorrect Permission Assignment for Critical Resource. The scope change indicator in the CVSS vector shows the impact extends beyond the vulnerable component, meaning data from tenants or users other than the attacker may be exposed. No authentication bypass, code execution, or integrity impact is associated with this issue.
Critical Impact
An authenticated attacker can retrieve sensitive information processed by M365 Copilot across trust boundaries without user interaction.
Affected Products
- Microsoft 365 Copilot (cloud service)
Discovery Timeline
- 2026-09-18 - CVE-2026-85887 published to NVD
- 2026-09-18 - Last updated in NVD database
Technical Details for CVE-2026-85887
Vulnerability Analysis
The vulnerability originates in how M365 Copilot assigns permissions to a critical resource involved in processing user prompts and returning generated content. Because the resource inherits or is granted broader access rights than intended, an authenticated user can request or receive data that should be restricted. The confidentiality impact is rated high, while integrity and availability remain unaffected. The scope change means the vulnerable Copilot component can leak information belonging to a security authority different from its own.
Root Cause
The root cause is an incorrect permission assignment on a resource that Copilot uses when handling grounding data, plugin responses, or shared session state. Access checks fail to enforce the tenant, user, or object-level boundary expected by the calling context. This class of defect, tracked as [CWE-732], typically results from overly permissive access control lists, missing authorization checks on server-side APIs, or misconfigured default permissions on shared objects.
Attack Vector
Exploitation occurs over the network against the Copilot service. The attacker must already hold a valid, low-privilege account and does not require user interaction. By issuing crafted requests that reference or induce Copilot to load the misprotected resource, the attacker can coerce the service into returning content outside their authorized view. Refer to the Microsoft Security Update Guide CVE-2026-85887 for vendor technical details.
No verified public proof-of-concept code is available. The vulnerability is described in prose because Microsoft has not published exploit details.
Detection Methods for CVE-2026-85887
Indicators of Compromise
- Unusual volumes of Copilot prompt requests from a single account followed by responses referencing data the user does not own.
- Copilot audit log entries showing access to resources, sites, or documents outside the user's normal working set.
- Anomalous plugin or connector invocations tied to accounts that historically do not use those integrations.
Detection Strategies
- Correlate Microsoft 365 unified audit log entries for CopilotInteraction events against the requesting user's SharePoint, OneDrive, and Exchange permissions to surface access outside expected scope.
- Baseline per-user Copilot query patterns and alert on sudden spikes in cross-tenant or cross-workspace references.
- Review Microsoft Purview eDiscovery and DLP telemetry for sensitive content appearing in Copilot responses to unauthorized recipients.
Monitoring Recommendations
- Ingest Microsoft 365 audit logs, Entra ID sign-in logs, and Copilot interaction telemetry into a centralized analytics platform for correlation.
- Enable Microsoft Purview auditing at the highest retention tier available to preserve Copilot activity for investigation.
- Track service principal and delegated permission changes on Graph API scopes used by Copilot.
How to Mitigate CVE-2026-85887
Immediate Actions Required
- Confirm that the Microsoft-hosted fix has been applied to your tenant by consulting the Microsoft Security Update Guide CVE-2026-85887.
- Review and tighten M365 Copilot licensing and access assignments to limit exposure to accounts that require the service.
- Audit sensitive SharePoint sites, OneDrive shares, and Teams channels for over-permissioned content that Copilot could surface.
Patch Information
This vulnerability affects a Microsoft cloud service. Remediation is delivered by Microsoft on the service side and does not require customer-installed patches. Verify the current status and any customer-side configuration guidance in the vendor advisory.
Workarounds
- Apply Microsoft Purview sensitivity labels and DLP policies to restrict Copilot processing of confidential content.
- Enforce least privilege on SharePoint, OneDrive, and Graph API permissions consumed by Copilot connectors and plugins.
- Disable or scope Copilot plugins and connectors that are not required for business operations.
# Configuration example: restrict Copilot to a pilot group via Entra ID assignment
# (Replace <group-object-id> with your security group)
Connect-MgGraph -Scopes "Application.ReadWrite.All","Directory.ReadWrite.All"
$copilotServicePlan = "Microsoft 365 Copilot"
Set-MgGroupLicense -GroupId <group-object-id> \
-AddLicenses @{ SkuId = "<copilot-sku-id>" } \
-RemoveLicenses @()
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
