CVE-2026-59118
Copilot Cowork Elevation of Privilege Vulnerability
Description
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
In plain language
AI Act nowCVE-2026-59118 is an authorization flaw in Copilot Cowork that could let an attacker gain higher access when a user clicks/uses the app from the network; small businesses that use Copilot Cowork should act now to ensure Microsoft’s fix is applied.
CVE-2026-59118 is an authorization weakness (CWE-285) in power apps / Copilot Cowork that can allow an unauthorized attacker to elevate privileges over the network by leveraging a user interaction (e.g., clicking/using a link) with insufficient permission checks; no attacker login is required.
What to do now
- Check whether you use Microsoft power apps and/or Copilot Cowork in any tenant, environment, or workflow.
- Open Microsoft’s update guidance for CVE-2026-59118 and confirm the fixed version(s) that apply to your deployment/tenant.
- Update/patch Copilot Cowork (and any related power apps components per the Microsoft guidance) to the fixed version as soon as possible.
- If you cannot patch immediately, restrict access paths to Copilot Cowork/power apps from untrusted networks and monitor for unusual authorization or data-change activity around the times users interact with links in the app.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
References
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-59118 and every CVE in our database. Create a free account — no credit card required.
Create Free Account