logo

Microsoft Copilot Studio Exploit Leaks Sensitive Cloud Data

ID: 1974671e-c731-5ec5-8de9-fb3143aa829e

STIX ID: report--1974671e-c731-5ec5-8de9-fb3143aa829e

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-08-21

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

**Executive summary:** Tenable researchers discovered an SSRF vulnerability in Microsoft Copilot Studio (CVE-2024-38206) that could be abused via crafted HTTP requests and SSRF bypasses to retrieve IMDS-managed identity tokens and access internal Azure resources (including read/write access to a Cosmos DB instance), potentially affecting multiple tenants sharing the service; Microsoft quickly mitigated the issue and no user action was required.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.