ShareLeak: Taking the Wheel of Microsoft’s Copilot Studio (CVE-2026-21520)
Bar Kaduri
March 5, 2026
The Capsule research team discovered a high severity indirect prompt injection vulnerability in Microsoft Copilot Studio that enables attackers to exfiltrate sensitive data through external SharePoint form.