CVE-2026-21520

HIGH WAF: High
CVSS 7.5 Published: 2026-01-22
CWE-77

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector

WAF Coverage Analysis

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
microsoftcopilot_studio-

References

Back to CVE Database