CVE-2026-47645: Microsoft 365 Copilot Business Chat Open Redirect Privilege Escalation
CVE-2026-47645 is a critical flaw in Microsoft 365 Copilot's Business Chat feature that allows attackers to trick users into visiting malicious websites by crafting deceptive links. When exploited, this open redirect vulnerability can enable an attacker to escalate their privileges within the targeted organization. The attack requires user interaction—specifically, a victim must click a malicious link—but no special access or complex conditions are needed to craft the exploit, making it a significant risk for organizations relying on Copilot for business communications.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-601
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-19 / 2026-06-26
NVD description (verbatim)
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability exists as an unvalidated URL redirection flaw (CWE-601) in Microsoft 365 Copilot's Business Chat component. An attacker can inject a crafted URL that appears legitimate within the chat interface but redirects users to an untrusted external site. The flaw allows privilege escalation over the network without requiring prior authentication. The CVSS 3.1 score of 8.8 (HIGH) reflects network-based exploitation, low complexity, no privilege requirements, and potential for complete compromise of confidentiality, integrity, and availability. The attack vector requires user interaction but is otherwise unrestricted in scope.
Business impact
This vulnerability threatens organizations' ability to securely use Microsoft 365 Copilot for internal collaboration and decision-making. Employees deceived into following malicious links could expose sensitive corporate data, enable credential theft, or provide attackers a foothold for lateral movement within the organization. For enterprises managing sensitive communications through Copilot—particularly in finance, legal, or strategic planning—unauthorized privilege escalation poses a material risk to governance and data integrity. The requirement for user interaction may reduce mass-exploitation risk but does not eliminate the threat posed by targeted social engineering campaigns.
Affected systems
Microsoft 365 Copilot, specifically the Business Chat feature, is affected. Organizations operating this service should assume all instances are vulnerable until patched. Confirm your deployment scope by reviewing Copilot enablement settings within your Microsoft 365 tenant and identifying which users have Business Chat access.
Exploitability
Exploitation is practical and requires moderate attacker sophistication. The attacker must craft a malicious link and deliver it to a target—either directly through chat, email, or social engineering. No zero-click behavior is present; victims must consciously click the link. However, because Business Chat operates within a trusted corporate environment where users may lower their guard, social engineering success rates could be elevated. The attack does not require authentication or special configuration, making it broadly applicable once a victim is identified.
Remediation
Apply the security update from Microsoft as soon as it becomes available. Until patching is complete, organizations should consider disabling Business Chat or restricting its availability to lower-risk user populations. Implement complementary controls: educate users on open redirect risks, enforce email link warnings and URL scanning, monitor for suspicious redirect patterns in logs, and enforce multi-factor authentication to reduce the impact of compromised credentials resulting from credential-harvesting redirects.
Patch guidance
Monitor the Microsoft Security Update Guide and your Microsoft 365 admin center for official patches to Copilot. Verify patches through the vendor advisory before deployment. Test patches in a non-production environment first, as Copilot updates can affect user workflows. Coordinate with stakeholders who depend on Business Chat to plan maintenance windows. Once patches are available, prioritize rapid deployment due to the HIGH severity rating and the ease of social engineering in a business context.
Detection guidance
Monitor network logs for unexpected outbound redirects or URL rewrites originating from Copilot infrastructure. Capture HTTP referrer logs from Business Chat interactions and flag any redirects to external, non-corporate domains. Implement Conditional Access policies to flag Business Chat sessions that redirect to untrusted URLs. Review user feedback and phishing reports for mentions of suspicious Copilot links. Consider UEBA (User and Entity Behavior Analytics) to detect unusual post-redirect activity patterns, such as rapid credential usage or privilege escalation attempts following a redirect event.
Why prioritize this
This vulnerability merits immediate attention due to its HIGH CVSS score, lack of complex exploitation barriers, and the privileged trust users place in internal collaboration tools. While not yet in the CISA KEV catalog, the combination of network exploitability, high impact, and social engineering potential makes it a prime target for adversaries seeking to compromise organizations at scale. Prioritization should reflect both the technical severity and the organizational dependence on Copilot for business-critical communications.
Risk score, explained
The CVSS 3.1 score of 8.8 reflects a network-accessible vulnerability with low attack complexity, no authentication requirement, and high impact across confidentiality, integrity, and availability. The requirement for user interaction (UI:R) prevents a perfect 9.8 score but does not significantly reduce risk in a social engineering context. The 'unchanged scope' (S:U) indicates the vulnerability is confined to the Copilot component itself, though privilege escalation outcomes can extend impact beyond that boundary.
Frequently asked questions
Will patching Copilot disrupt ongoing Business Chat conversations?
Typically, security patches to Copilot do not terminate active conversations, but behavior and feature availability may change. Test in a staging environment and communicate maintenance windows to stakeholders to minimize disruption.
Can we rely on email security tools to block malicious Copilot redirects?
Email tools do not protect against links shared within Copilot's chat interface itself. Layer defenses with network monitoring, Conditional Access policies, and user training to catch redirects at multiple points.
What should we do if we suspect a user clicked a malicious Copilot link?
Immediately reset the user's credentials, review their account activity for unauthorized privilege escalation, audit their access to sensitive resources, and check for lateral movement. Consider an incident response investigation if multiple users were compromised.
Is there a temporary workaround to reduce risk without disabling Copilot entirely?
Restrict Business Chat access to specific user groups while patches are validated. Enforce strict Conditional Access policies requiring step-up authentication for high-risk actions post-redirect. However, these are mitigations, not fixes—prioritize patching.
This analysis is based on vulnerability data as of the publication date and reflects publicly available information about CVE-2026-47645. Organizations should verify all patch version numbers and remediation guidance against official Microsoft Security Update advisories before deployment. No exploit code or proof-of-concept is provided. This is not a substitute for your organization's vulnerability assessment, risk management, or incident response processes. Consult with Microsoft Support and your security team regarding your specific environment. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35258HIGHOracle WebLogic Server Console Open Redirect Vulnerability – Analysis & Patch Guidance
- CVE-2026-35259HIGHOracle WebLogic Server Console RCE – CVSS 8.8 Analysis & Patch Guidance
- CVE-2026-35302HIGHOracle WebLogic Server Console Vulnerability (CVSS 8.3)
- CVE-2026-40961HIGHApache Airflow Open Redirect Vulnerability (CVSS 7.2)
- CVE-2026-46796HIGHOracle WebCenter Sites Open Redirect Vulnerability (CVSS 8.0)
- CVE-2026-46806HIGHOracle WebCenter Content Open Redirect Vulnerability – CVSS 8.2
- CVE-2026-46894HIGHOracle iSupplier Portal CSRF and Open Redirect Vulnerability—Impact & Remediation
- CVE-2026-46955HIGHOracle E-Business Suite Human Resources Vulnerability – HIGH Severity