CVE-2026-21520
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
22/01/2026
Last modified:
22/01/2026
Description
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



