CVE-2026-42893
published 2026-05-12CVE-2026-42893: Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.40%
32.2th percentile
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_outlook_for_ios | >= 1.0.0 < 5.2617.1 | 5.2617.1 |
| microsoft | outlook | < 5.2617.1 | 5.2617.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h35m-vhjw-vqxj: Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tamperi
ghsa_unreviewed·2026-05-12
CVE-2026-42893 [HIGH] CWE-77 GHSA-h35m-vhjw-vqxj: Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tamperi
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.
VulDB
Microsoft Outlook up to 5.5 on iOS command injection
vuldb·2026-05-12
CVE-2026-42893 [LOW] Microsoft Outlook up to 5.5 on iOS command injection
A vulnerability, which was classified as problematic, has been found in Microsoft Outlook on iOS. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in command injection.
This vulnerability is identified as CVE-2026-42893. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
2026-05-12
Published