Three information disclosure flaws in Microsoft Copilot, Copilot Studio and M365 Copilot
Microsoft disclosed three CVEs affecting Copilot Studio, Copilot and M365 Copilot (CVE-2026-21520, CVE-2026-21521, CVE-2026-24307) that allow unauthorized or unauthenticated attackers to disclose sensitive information over a network. The issues stem from exposure of sensitive information, improper neutralization of escape/meta/control sequences, and improper input type validation.
Disclosed 22 January 2026 · Record updated 13 September 2026
Impact
Attackers could view or disclose sensitive information over a network; in the Copilot Studio case without authentication.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-21520
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-21521
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-24307
