CVE-2026-42824: Missing authentication for critical function in M365

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Related briefings

Browse the CVE database

Read the full analysis on IntelFusions