type: cve · created: 2026-09-19 · updated: 2026-09-19 · tags: [cve] · confidence: medium · severity: critical · affected_sectors: [global] · au_impact: false
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
The same batch carried CVE-2026-85885 (CVSS 9.9), command injection in Microsoft 365 Copilot, CVE-2026-85878 (CVSS 9.9), improper authorisation in Azure Database for PostgreSQL, and CVE-2026-87701 (CVSS 9.6), improper neutralisation in Azure Cosmos DB.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-87701 |
| CVSS | 9.6 (critical) |
| Vendor / product | Microsoft — Azure Cosmos DB |
| Reported | 2026-09-19 |