


Perceptive Security
SOC/SIEM Consultancy

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Published:
22 April 2026 at 22:00:00
Alert date:
23 April 2026 at 23:04:51
Source:
nvd.nist.gov
Enterprise Applications, Cloud & Virtualization
A URL redirection vulnerability (open redirect) in Microsoft 365 Copilot allows unauthorized attackers to redirect users to untrusted sites. This vulnerability can be exploited to elevate privileges over a network. The issue affects M365 Copilot and represents a significant security risk for organizations using Microsoft's AI-powered productivity tool. Attackers could potentially use this vulnerability to conduct phishing attacks or gain unauthorized access to network resources.
Technical details
Mitigation steps:
Affected products:
M365 Copilot
Microsoft 365 Copilot
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33102
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33102
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
