CVE-2026-26137

Publication date

2026-03-19 21:06:26

Family

microsoft

State

PUBLISHED

Description

Server-side request forgery (ssrf) in Microsoft 365 Copilots Business Chat allows an authorized attacker to elevate privileges over a network.