{"@odata.context":"https://api.msrc.microsoft.com/sug/v2.0/sugodata/v2.0/ja-JP/$metadata#vulnerability/$entity","id":"00000000-0000-0000-0000-00005d7d9691","releaseDate":"2026-09-17T07:00:00-07:00","cveNumber":"CVE-2026-78501","cveTitle":"Microsoft 365 Copilot Business Chat \u306e\u60c5\u5831\u6f0f\u3048\u3044\u306e\u8106\u5f31\u6027","releaseNumber":"2026-Sep","vulnType":"Security Vulnerability","latestRevisionDate":"2026-10-06T07:00:00-07:00","cweList":["CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')","CWE-923: Improper Restriction of Communication Channel to Intended Endpoints"],"cweDetailsListForSearch":["cwe: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')","cweUrl: https://cwe.mitre.org/data/definitions/77.html","cwe: CWE-923: Improper Restriction of Communication Channel to Intended Endpoints","cweUrl: https://cwe.mitre.org/data/definitions/923.html"],"mitreText":"CVE-2026-78501","mitreUrl":"https://www.cve.org/CVERecord?id=CVE-2026-78501","publiclyDisclosed":"No","exploited":"No","latestSoftwareReleaseId":4,"latestSoftwareRelease":"\u5bfe\u8c61\u5916","olderSoftwareReleaseId":0,"denialOfService":"\u5bfe\u8c61\u5916","tag":"Microsoft 365 Copilot's Business Chat","issuingCna":"Microsoft","issuingCnaId":100000001,"severityId":100000000,"severity":"\u7dca\u6025","impactId":100000003,"impact":"\u60c5\u5831\u6f0f\u3048\u3044","langCode":"ja-JP","baseScore":"7.4","temporalScore":"6.4","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C","vectorStringSource":"Microsoft","isMariner":false,"customerActionRequired":false,"customerActionRequiredId":2,"cweDetailsList":[{"keys":["cwe","cweUrl"],"values":["CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')","https://cwe.mitre.org/data/definitions/77.html"]},{"keys":["cwe","cweUrl"],"values":["CWE-923: Improper Restriction of Communication Channel to Intended Endpoints","https://cwe.mitre.org/data/definitions/923.html"]}],"articles":[{"articleType":"FAQ","description":"<p><strong>\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3078\u306e\u30ea\u30f3\u30af\u3084\u3001\u3053\u306e\u8106\u5f31\u6027\u304b\u3089\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306e\u5b9f\u884c\u3059\u3079\u304d\u624b\u9806\u3092\u8a18\u8f09\u3057\u305f\u624b\u9806\u304c\u306a\u3044\u306e\u306f\u306a\u305c\u3067\u3059\u304b?</strong></p>\n<p>\u3053\u306e\u8106\u5f31\u6027\u306f Microsoft \u306b\u3088\u3063\u3066\u65e2\u306b\u5b8c\u5168\u306b\u7de9\u548c\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u30b5\u30fc\u30d3\u30b9\u306e\u30e6\u30fc\u30b6\u30fc\u304c\u5b9f\u884c\u3059\u308b\u30a2\u30af\u30b7\u30e7\u30f3\u306f\u3042\u308a\u307e\u305b\u3093\u3002\u3053\u306e CVE \u306e\u76ee\u7684\u306f\u3001\u3055\u3089\u306a\u308b\u900f\u660e\u6027\u3092\u63d0\u4f9b\u3059\u308b\u3053\u3068\u3067\u3059\u3002</p>\n<p>\u300c<a href=\"https://aka.ms/MSRC-Cloud-CVEs\">\u900f\u660e\u6027\u306e\u5411\u4e0a\u306b\u5411\u3051\u3066\u300d\u3092\u3054\u89a7\u304f\u3060\u3055\u3044\u3002\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001\u300c\u30af\u30e9\u30a6\u30c9 \u30b5\u30fc\u30d3\u30b9 CVE \u306e\u516c\u8868</a>\u300d\u3092\u3054\u89a7\u304f\u3060\u3055\u3044\u3002</p>\n","ordinal":10000},{"title":"Copilot\u30c1\u30e3\u30c3\u30c8(Microsoft Edge)\u60c5\u5831\u958b\u793a\u8106\u5f31\u6027","articleType":"100000000","description":"<p>Copilot Chat(Microsoft Edge)\u3067\u30b3\u30de\u30f3\u30c9\u3067\u4f7f\u7528\u3055\u308c\u308b\u7279\u6b8a\u8981\u7d20(\u300c\u30b3\u30de\u30f3\u30c9\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u300d)\u3092\u4e0d\u9069\u5207\u306b\u7121\u52b9\u5316\u3059\u308b\u3068\u3001\u4e0d\u6b63\u306a\u653b\u6483\u8005\u304c\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u4e0a\u3067\u60c5\u5831\u3092\u6f0f\u3089\u3059\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002</p>\n","ordinal":10000}],"revisions":[{"cveNumber":"CVE-2026-78501","version":1.1,"revisionDate":"2026-10-06T07:00:00-07:00","initialDate":"0001-01-01T00:00:00Z","description":"<p>Updated an acknowledgement. This is an informational change only.</p>\n","unformattedDescription":"Updated an acknowledgement. This is an informational change only.","notificationNeeded":false,"notificationSent":false,"sourceId":"a5dce541-95c1-f111-aaad-000d3a3b5846"},{"cveNumber":"CVE-2026-78501","version":1,"revisionDate":"2026-09-17T07:00:00-07:00","initialDate":"0001-01-01T00:00:00Z","description":"<p>Information published.</p>\n","unformattedDescription":"Information published.","notificationNeeded":true,"notificationSent":true,"sourceId":"26428ec0-34a7-f111-93a1-000d3ac5fb71"}]}