Vulnerability Brief

CVE-2026-47645

  • Severity: HIGH
  • CVSS score: 8.8

Technical summary

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.