CVE-2026-21520 | Microsoft Copilot Studio command injection (EUVD-2026-4504 / CNNVD-202601-3922)
A vulnerability categorized as critical has been discovered in Microsoft Copilot Studio. Affected by this vulnerability is an unknown functionality. Such manipulation leads to command injection.
This vulnerability is listed as CVE-2026-21520. The attack may be performed from remote. There is no available exploit.
This product is a managed service, so users are unable to manage vulnerability countermeasures on their own.