ReviewCritical
CVE-2026-59118
Microsoft Copilot Cowork, power apps
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
- CVSS
- 9.3
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.08.07
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
The CVSS severity warrants an early asset and exposure review.
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
Confirm exposure before applying a vendor-supported change.
Confirm that Microsoft Copilot Cowork, power apps and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.