Microsoft Copilot Studio Exploit Leaks Sensitive Cloud Data
ID: 1974671e-c731-5ec5-8de9-fb3143aa829e
STIX ID: report--1974671e-c731-5ec5-8de9-fb3143aa829e
Feed Name: Dark Reading
Date Published: 2024-08-21
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
**Executive summary:** Tenable researchers discovered an SSRF vulnerability in Microsoft Copilot Studio (CVE-2024-38206) that could be abused via crafted HTTP requests and SSRF bypasses to retrieve IMDS-managed identity tokens and access internal Azure resources (including read/write access to a Cosmos DB instance), potentially affecting multiple tenants sharing the service; Microsoft quickly mitigated the issue and no user action was required.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
