PT-2026-4307 · Microsoft · Copilot Studio
CVE-2026-21520
·
Published
2026-01-22
·
Updated
2026-09-09
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Copilot Studio versions prior to January 15, 2026
Description
An issue in Microsoft Copilot Studio allows an unauthenticated remote attacker to view sensitive information via a network attack vector. The flaw is rooted in a lack of data sanitization at the control level and a failure to separate trusted instructions from user input. This enables prompt injection, where attackers manipulate form inputs—such as a poisoned SharePoint field—to override agent behavior and silently exfiltrate sensitive data. Exposed information may include tenant data, agent configurations, connector parameters, sensitive metadata, and diagnostic details. In real-world scenarios, this has been used to steer the agent into emailing customer data to an attacker.
Recommendations
Apply the MSRC updates released on January 15, 2026.
Review all connectors and tokens to ensure no unauthorized access persists.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Copilot Studio