CVE-2026-21520, dubbed "ShareLeak" by Capsule Security, is an indirect prompt injection vulnerability in Microsoft Copilot Studio. According to the provided reporting, the issue arose because attacker-controlled input from a public-facing SharePoint form/comment field could be concatenated with the agent’s system instructions without adequate input sanitization or trust-boundary separation. By placing a crafted payload in SharePoint input, an unauthenticated attacker could inject a fake system-role style instruction into the Copilot Studio agent’s context window, override the agent’s intended behavior, and cause it to query connected SharePoint Lists for customer data and then send that data through an authorized Outlook action to an attacker-controlled email address. The vulnerability is described as a prompt-injection-driven sensitive information exposure over a network vector, and the broader attack pattern is characterized in the source material as OWASP ASI01 Agent Goal Hijack.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An indirect prompt injection vulnerability in Microsoft Copilot Studio that enabled a specific data-exfiltration path and was notable because a CVE was assigned to a prompt injection issue in an agentic platform.
An indirect prompt injection vulnerability in Microsoft Copilot Studio that allowed attacker-controlled input from a public-facing SharePoint form field to be concatenated with system instructions, enabling data exfiltration via legitimate Outlook actions.
A high-severity prompt injection vulnerability in Microsoft Copilot triggered via SharePoint form input that could exfiltrate customer data to an attacker-controlled email.
An indirect prompt injection vulnerability in Microsoft Copilot Studio that allows attacker-controlled input from SharePoint forms to override agent instructions and exfiltrate data via authorized Outlook actions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.