PT-2026-4307 · Microsoft · Copilot Studio

CVE-2026-21520

·

Published

2026-01-22

·

Updated

2026-09-09

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Copilot Studio versions prior to January 15, 2026
Description An issue in Microsoft Copilot Studio allows an unauthenticated remote attacker to view sensitive information via a network attack vector. The flaw is rooted in a lack of data sanitization at the control level and a failure to separate trusted instructions from user input. This enables prompt injection, where attackers manipulate form inputs—such as a poisoned SharePoint field—to override agent behavior and silently exfiltrate sensitive data. Exposed information may include tenant data, agent configurations, connector parameters, sensitive metadata, and diagnostic details. In real-world scenarios, this has been used to steer the agent into emailing customer data to an attacker.
Recommendations Apply the MSRC updates released on January 15, 2026. Review all connectors and tokens to ensure no unauthorized access persists.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00838
CVE-2026-21520

Affected Products

Copilot Studio