DIRAS TAKE
Urgent: this is a pre-auth remote privilege escalation (no login required), so prioritize containment and applying vendor guidance or patches as soon as they are available.
What is CVE-2026-80098?
An unauthenticated network attacker can elevate privileges in Microsoft Copilot Studio due to improper verification of cryptographic signatures, tracked as CVE-2026-80098. Microsoft reports the issue affects Microsoft Copilot Studio but does not list specific fixed versions in the advisory. Exploitation requires network access and no valid credentials or user interaction, allowing remote attackers to present malformed or forged signatures to bypass integrity checks and gain higher privileges. The weakness is classified as CWE-347 (Improper Verification of Cryptographic Signature).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Microsoft Microsoft Copilot Studio are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Microsoft Copilot Studio | - |
Is CVE-2026-80098 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-80098
- Apply Microsoft’s official updates or guidance for Copilot Studio as soon as they are published.
- Restrict network exposure of Copilot Studio to trusted networks and block unnecessary internet access.
- Monitor logs and alert on anomalous authentication or signature verification failures.
- Rotate and tightly control keys, certificates, and signing credentials used by Copilot Studio where feasible.
Frequently asked questions
Is CVE-2026-80098 being actively exploited?
There are no public reports of active exploitation of CVE-2026-80098 as of 2026-09-30.
Which Microsoft Copilot Studio versions are affected by CVE-2026-80098?
The advisory identifies Microsoft Copilot Studio as affected but does not list specific version numbers or fixed releases.
Is there a patch for CVE-2026-80098?
Microsoft has indicated a patch is available or planned; follow Microsoft’s Copilot Studio guidance and apply updates when provided.
Does CVE-2026-80098 require authentication?
No; the vulnerability allows unauthenticated remote attackers to exploit improper signature verification without valid credentials.
References
- nvd.nist.gov/vuln/detail/CVE-2026-80098
- cve.org/CVERecord?id=CVE-2026-80098
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80098
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026