Aug 2026: Copilot Cowork Elevation of Privilege Vulnerability
CVE-2026-59118 Published on August 6, 2026

Copilot Cowork Elevation of Privilege Vulnerability
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

Vendor Advisory NVD

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-59118 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-59118

stack.watch emails you whenever new vulnerabilities are published in Microsoft Power Apps or Microsoft Copilot Cowork. Just hit a watch button to start following.

 
 

Affected Versions

Microsoft Copilot Cowork Version - is affected by CVE-2026-59118