CVE-2026-41106 is a critical open redirect vulnerability in Microsoft 365 Copilot that allows an unauthenticated attacker to elevate privileges over a network. Given the 9.3 CVSS score and network attack vector, this flaw could be leveraged to hijack authentication flows or session tokens tied to Copilot's integrated services.
Updated Jul 5, 2026 · CVSS 9.3