Ryft Blog
Research

ShareLeak: Taking the Wheel of Microsoft’s Copilot Studio (CVE-2026-21520)

Bar Kaduri
March 5, 2026

The Capsule research team discovered a high severity indirect prompt injection
vulnerability in Microsoft Copilot Studio that enables attackers to exfiltrate sensitive data
through external SharePoint form.

Table of Contents

Read more articles