CVE-2026-21520
Published: 22 January 2026
Summary
CVE-2026-21520 is a high-severity Command Injection (CWE-77) vulnerability in Microsoft Copilot Studio. Its CVSS base score is 7.5 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 25.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
This vulnerability is AI-related — categorised as Enterprise AI Assistants.
Threat & Defense at a Glance
Threat & Defense Details
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Remote unauthenticated network exploitation of public-facing Copilot Studio service via command injection (CWE-77) directly enables initial access and arbitrary command execution.
NVD Description
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector
Deeper analysisAI
CVE-2026-21520 is a vulnerability in Microsoft Copilot Studio that results in the exposure of sensitive information to an unauthorized actor. It allows an unauthenticated attacker to view sensitive data through a network-based attack vector. The issue has a CVSS v3.1 base score of 7.5, rated as High severity, with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, and is associated with CWE-77 (Command Injection). The vulnerability was published on 2026-01-22.
An unauthenticated attacker (PR:N) can exploit this vulnerability remotely over the network (AV:N) with low complexity (AC:L) and without requiring user interaction (UI:N). Successful exploitation enables the attacker to obtain high-impact confidentiality disclosures (C:H) of sensitive information, with no impact on integrity or availability.
Mitigation details are available in the official advisory from the Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21520.
Details
- CWE(s)
Affected Products
AI Security AnalysisAI
- AI Category
- Enterprise AI Assistants
- Risk Domain
- N/A
- OWASP Top 10 for LLMs 2025
- None mapped
- Classification Reason
- Matched keywords: copilot