CVE-2026-42824
CVSS 6.5 MEDIUM: improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an… EPSS 8% (94th percentile), up from 0.5%.
AI · 88 days ago
A real microsoft.com search link can carry instructions, not just a query, so the usual trust checks miss the attack before Copilot starts reading internal data. In SearchLeak, the user only clicks once; the link’s q parameter is treated like a prompt, and Copilot can be steered toward mailbox or file content that the user never typed out.
Varonis published a proof of concept for CVE-2026-42824, and Microsoft says it already applied backend mitigation. The chain affects Microsoft 365 Copilot Enterprise and Microsoft Copilot Enterprise Search, with exposed data including emails, calendar items, OneDrive files, SharePoint documents, and secrets such as MFA codes and passwords.
The risk is broader than one bug class. Any AI assistant that accepts instructions through links or prompts and can reach internal content inherits the same trust problem, even when the destination domain is legitimate.
CVSS 6.5 MEDIUM: improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an… EPSS 8% (94th percentile), up from 0.5%.
5 sources covering this story
M365 Copilot SearchLeak: Your prompt injection attack surface just got bigger
Although not the first of its kind, researchers’ POC attack against Microsoft’s M365 Copilot Enterprise underscores parameter-to-prompt (P2P) injections as a potentially broad threat.
Critical Copilot vulnerability allowed hackers to steal 2FA code from users
SearchLeak exploit shows why the industry's approach to LLM security fails over and over.
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Microsoft fixed a critical Copilot Enterprise Search flaw that could expose emails, calendars, and indexed files through one trusted link.
Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
The critical, three-stage attack is now patched, but it's part of a new group of AI prompt-injection issues that use hidden URLs and other variables.
New attack turned Microsoft 365 Copilot into 1-click data theft tool
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL.
Part of the PlainSec briefing for 2026-06-20